macOS Flaw Allowed Standard Users to Disable CrowdStrike and Kandji Security Tools
Cybersecurity defence firm XM Cyber has found a security flaw in the Apple macOS operating system. The issue centres on a vulnerability within the core communication architecture used by top enterprise protective software. It is basically a structural gap that allows ordinary system accounts to fully bypass normal security boundaries.
Chaining NIB Injections and XPC Services
Many Mac applications use a background communication system called XPC to allow different parts of the software to communicate with each other. For example, a visible app window might need to send commands to a hidden background service that runs with deep system root access.
According to XM Cyber researchers, these background services usually trust any message that looks like it comes from their own app by checking a code signature known as a CDHash.
However, XM Cyber discovered that hackers can trick this setup by combining a method called CDHash cache exploitation with...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE