Posts
49 posts since 2019.
2026
2025
2024
2023
2022
2021
- CVE-2021-30808 - CVE-2021-1784 strikes back - TCC bypass via mounting
- Getting started in macOS security
- GateKeeper - Not a Bypass (Again)
- macOS Monterey Shortcuts - First look
- NOCVE - TeamViewer Local Privilege Escalation Vulnerability
- Experiences with Apple Security Bounty
- CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter
- About com.apple.private.security.clear-library-validation
- Divide and Conquer - A technique to bypass NextGen AV
2020
- CVE-2020-9771 - Reversing Engineering the Fix
- NOCVE - Microsoft Teams for macOS Local Privilege Escalation
- Let's talk macOS Authorization
- CVE-2020-9771 - mount_apfs TCC bypass and privilege escalation
- CVE-2020-14977 - Secure coding XPC Services - Part 5 - PID reuse attacks
- CVE-2020-14978 - Secure coding XPC Services - Part 4 - Improved client authorization
- The AMFI MACF policy system call
- CVE-2020-0984 - Secure coding XPC Services - Part 3 - Incorrect client verification
- Kernel Debugging macOS with SIP
- Secure coding XPC Services - Part 2 - Checking CS (CodeSigning) flags of the client
- TALK - Exploiting directory permissions on macOS
- CVE-2019-20057 - Secure coding XPC services - Part 1 - Why EvenBetterAuthorization is not enough?
2019
- GateKeeper - Bypass or not bypass?
- CVE-2020-14974 & CVE-2020-14975 - IOBit Unlocker 1.1.2 - Local Privilege Escalation
- NOCVE - Few click RCE via GitHub Desktop macOS client with Gatekeeper bypass and custom URL handlers
- UninstallString - a possible LPE via Social Engineering
- A simple protection against HMValidateHandle technique
- DYLD_INSERT_LIBRARIES DYLIB injection in macOS / OSX
- TALK - macOS - Getting root with benign AppStore apps
- CVE-2020-14976 - GNS3 ubridge SETUID bit - arbitrary file read
- CVE-2019-5514 - VMware Fusion 11 - Guest VM RCE