Finding Vulnerabilities in Apple Packages at Scale
Intro#
This article summarizes work we performed in 2024, which we shared in our "Finding Vulnerabilities in Apple Packages at Scale" talk at MacDevOpsYVR and SecurityFest conferences earlier this year.
In macOS, two daemons handle package installation: installd and system_installd. The first is invoked when we install third-party packages, the second is for Apple-signed packages. We'll revisit why vulnerabilities in Apple-signed packages can be devastating, focusing on system_installd, which is more frequently abused.
...
The full blog was published at my company's (Iru, formerly Kandji) website: https://www.iru.com/blog/finding-vulnerabilities-in-apple-packages