![]() "We found that the vulnerability lies in how Apple-signed packages with post-install scripts are installed. The Shrootless security issue was discovered by Microsoft's researchers after noticing that the system_installd daemon had the .inheritable entitlement which allowed any child process to fully bypass SIP filesystem restrictions. SIP (also known as rootless) is a macOS security technology that blocks potentially malicious software from modifying protected folders and files by restricting the root user account and limiting the actions it can perform on protected parts of the OS.īy design, SIP only allows processes signed by Apple or those with special entitlements (i.e., Apple software updates and Apple installers) to modify these protected parts of macOS. The Microsoft 365 Defender Research Team reported the vulnerability dubbed Shrootless (now tracked as CVE-2021-30892) to Apple by via the Microsoft Security Vulnerability Research (MSVR). Attackers could use a new macOS vulnerability discovered by Microsoft to bypass System Integrity Protection (SIP) and perform arbitrary operations, elevate privileges to root, and install rootkits on vulnerable devices. ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |