threat-intel
Apple's MacOS Gap Lets Users Disable Security Tools
High
Summary
This article details a macOS security vulnerability discovered by XM Cyber that allows standard users to disable enterprise security tools like CrowdStrike Falcon EDR and Kandji MDM without administrator privileges. The flaw stems from how macOS caches application trust information (CDHash) and enables an attacker to impersonate trusted components and execute privileged commands via XPC services. While Apple has not addressed the issue, vendors like Iru Inc. have released patches, and XM Cyber has developed a tool, XPC Hunter, to aid in identifying similar vulnerabilities.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
