theevilbit

The diskarbitrationd and storagekitd Audit Story Part 3

1 min readmacoslpetccvulnerabilitycve

Intro#

Over the past two parts of this series, we've explored vulnerabilities in macOS's diskarbitrationd daemon. In part 1, we explored how an attacker could use it to escape the sandbox or escalate privileges. In part 2, we explored how a directory traversal attack could be used to bypass Transparency, Consent, and Control (TCC) protections.

In this third and final part of the series, we will discuss a vulnerability which impacted storagekitd. The vulnerability allowed an attacker to escalate their privileges to root. Apple fixed this and assigned CVE-2024-27848. However, because the patch was insufficient, we could bypass it and perform the same attack; moreover we could also fully bypass TCC. This issue is identified now as CVE-2024-44210.

...

The full blog was published at my company's (Iru, formerly Kandji) website: https://www.iru.com/blog/macos-audit-story-part3