CommunityNews

CommunityNews

Process injection: breaking all macOS security layers with a single vulnerability

Process injection: breaking all macOS security layers with a single vulnerability.
If you have created a new macOS app with Xcode 13.2, you may noticed this new method in the template:

  • (BOOL)applicationSupportsSecureRestorableState:(NSApplication *)app { return YES; } This was added to the Xcode template to address a process injection vulnerability we reported!
    In macOS 12.0.1 Monterey, Apple fixed CVE-2021-30873. This was a process injection vulnerability affecting (essentially) all macOS AppKit-based applications. We reported this vulnerability to Apple, along with methods to use this vulnerability to escape the sandbox, elevate privileges to root and bypass the filesystem restrictions of SIP.

Read in full here:

This thread was posted by one of our members via one of our news source trackers.

Popular Macos topics Top

First poster: bot
Google ‘colluded’ with Facebook to bypass Apple privacy. Amended Texas complaint alleges backroom efforts to maintain ad dominance and m...
New
New
First poster: bot
Apple’s Director of Machine Learning Resigns Due to Return to Office Work. Apple’s director of machine learning, Ian Goodfellow, has res...
New
First poster: bot
Apple’s mixed reality headset will reportedly feature content created by Hollywood directors. Apple is reportedly partnering with Jon Fa...
New
New
New
New
First poster: bot
Steve Jobs negotiates Apple’s deal with Microsoft. Greg, Here is a review of the terms we last discussed, as well as some issues I have ...
New
First poster: bot
Report: Apple to Move a Part of its Embedded Cores to RISC-V, Stepping Away from Arm ISA. According to Dylan Patel of SemiAnalysis sourc...
New
First poster: DevotionGeo
The new Mac Pro chip could double or quadruple the power of the M2 Max. Apple’s expected to launch the new Mac Pro next year.
New

Other popular topics Top

DevotionGeo
I know that these benchmarks might not be the exact picture of real-world scenario, but still I expect a Rust web framework performing a ...
New
dasdom
No chair. I have a standing desk. This post was split into a dedicated thread from our thread about chairs :slight_smile:
New
AstonJ
I’ve been hearing quite a lot of comments relating to the sound of a keyboard, with one of the most desirable of these called ‘thock’, he...
New
AstonJ
I have seen the keycaps I want - they are due for a group-buy this week but won’t be delivered until October next year!!! :rofl: The Ser...
New
AstonJ
If you are experiencing Rails console using 100% CPU on your dev machine, then updating your development and test gems might fix the issu...
New
AstonJ
Saw this on TikTok of all places! :lol: Anyone heard of them before? Lite:
New
PragmaticBookshelf
Build efficient applications that exploit the unique benefits of a pure functional language, learning from an engineer who uses Haskell t...
New
PragmaticBookshelf
Author Spotlight: Karl Stolley @karlstolley Logic! Rhetoric! Prag! Wow, what a combination. In this spotlight, we sit down with Karl ...
New
First poster: bot
zig/http.zig at 7cf2cbb33ef34c1d211135f56d30fe23b6cacd42 · ziglang/zig. General-purpose programming language and toolchain for maintaini...
New
AstonJ
If you’re getting errors like this: psql: error: connection to server on socket “/tmp/.s.PGSQL.5432” failed: No such file or directory ...
New