theevilbit

CrashOne - A Starbucks Story - CVE-2025-24277

1 min readmacoslpesandboxvulnerabilitycve

Intro#

On a cold autumn day in Budapest in 2024, I met independent security researcher Gergely Kalman at a local Starbucks to swap ideas, dead ends, and updates on our research. Over coffee, we started talking about crash logs, and that's when we stumbled onto something big.

This article explains how that thread led to CVE-2025-24277: a sandbox escape and local privilege escalation in the osanalyticshelperd process that allows a standard user to gain root on macOS. We worked through several technical obstacles to build a reliable exploit, and we presented the results at Hexacon and Objective By The Sea.

...

The full blog was published at my company's (Iru, formerly Kandji) website: https://www.iru.com/blog/crashone-cve-2025-24277-macos-sandbox-escape