
CVE-2020-9771: macOS AmnesiaStealer — Steals Data, Hijacks Browsers (June 2024)
CVE-2020-9771 — macOS AmnesiaStealer
CVE-2020-9771 is a high-severity vulnerability exploited by AmnesiaStealer, a Rust-based malware targeting macOS systems. This threat enables attackers to steal passwords, keychain data, Safari cookies, Apple Notes, and browser information, while also granting remote control over victims' browser sessions. The vulnerability is actively exploited in the wild, with no vendor patch currently available.
Attack Vector
Attackers distribute AmnesiaStealer via a fake GitHub download page, tricking users into installing a trojanized application. Once executed, the malware bypasses macOS security controls, overwrites keychain encryption keys to facilitate ongoing decryption of sensitive data, and establishes a command-and-control channel. This allows exfiltration of credentials, documents, and browser artifacts, and provides attackers with full interactive access to browser sessions. The malware operates stealthily, evading standard endpoint protections.
Who Is at Risk
All macOS users, especially those downloading software from unofficial or spoofed GitHub repositories, are at risk. No specific organizations have been confirmed as affected, but the attack is global in scope and targets both individuals and enterprises using macOS endpoints.
Patch & Mitigate
- Patch: No official patch is available as of June 2024. Monitor Apple advisories for updates.
- Workaround: Block access to suspicious GitHub download pages and enforce application whitelisting. Restrict installation of unsigned or unverified software.
- Detect: Monitor for unusual outbound connections, unauthorized access to keychain files, and browser session hijacking. Review logs for unsigned binary execution and unexpected changes to keychain encryption keys.
MITRE ATT&CK
- TA0005 — Defense Evasion: AmnesiaStealer bypasses macOS security controls and operates without detection.
- TA0009 — Collection: The malware collects credentials, browser data, and sensitive documents from infected hosts.
- TA0011 — Command and Control: Establishes persistent remote access for interactive browser session control.
Source: https://www.securityweek.com/amnesiastealer-macos-malware-steals-data-controls-browser-sessions/
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

