macOS Privilege Escalation Lets Standard Users Disable EDR and MDM (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Standard users can disable EDR/MDM via XPC cached trust abuse.
- CrowdStrike and Kandji have patches; many apps remain vulnerable.
- Open-source XPC Hunter tool detects vulnerable macOS applications.
"A macOS vulnerability disclosed by XM Cyber allows standard users to abuse the XPC service to disable endpoint detection and response (EDR) and mobile device management (MDM) tools. The flaw lies in cached code-signature trust; an attacker can launch a legitimate app, tamper with it, and inherit its trusted status to call privileged functions without authentication. CrowdStrike and Kandji have released patches, but many other macOS apps remain exposed. An open-source scanning tool, XPC Hunter, has been released."
no comments yet.