Evernote’s Mac app had a vulnerability that could have allowed an attack to remotely launch malicious code …
TechCrunch explains the issue.
Dhiraj Mishra, a security researcher based in Dubai, reported the bug to Evernote on March 17. In a blog post showing his proof-of-concept, Mishra showed TechCrunch that a user only had to click a link masked as a web address, which would open a locally stored app or file unhindered and without warning […]
The bug could allow an attacker to remotely run malicious commands on any macOS computer with Evernote installed.
Mishra posted a video (below) on his blog demonstrating how it worked, where the user clicking on what appears to be a webpage link actually opens Calculator. He picked a harmless example for his proof of concept, but a bad actor could of course have done something much more worrying.
The security researcher notified Evernote and waited for them to fix it before disclosing the bug.
Evernote spokesperson Shelby Busen confirmed the bug had been fixed, and said the company “appreciates” the contributions from security researchers […]
Since the fix went into effect, Evernote now warns users when they click a link that opens a file on their Mac.