

macOS exploit found by Microsoft could bypass system protection
source link: https://9to5mac.com/2023/05/30/macos-exploit-microsoft/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.


Apple introduced System Integrity Protection (SIP) with OS X El Capitan in 2015, and it essentially adds multiple layers of security that blocks apps from accessing and modifying system files at a root level. While users can manually disable this feature, it’s not exactly easy to do so. But Microsoft found an exploit that could let attackers bypass SIP.
Microsoft details how it found the “Migraine” exploit in macOS
As the company shared on its Security blog, a vulnerability named “Migraine” could bypass macOS’ System Integrity Protection and lead to arbitrary code execution on a device. The exploit is so named because it’s related to the macOS Migration Assistant, a native tool that helps users move data from a Mac or Windows PC to another Mac.
As Microsoft explained, bypassing SIP can lead to “serious consequences,” since this gives attackers access to all system files, which makes it easy to install malware and rootkits. The exploit was able to do this using a special entitlement designed to give unrestricted root access to the Migration Assistant app.
In a normal situation, the Migration Assistant tool is only accessible during the setup process of a new user account, which means that hackers not only need to force a complete system sign-out, but also need to have physical access to the computer. But to demonstrate the potential risk of this exploit, Microsoft showed that there was a way to take advantage of it without worrying about the limitations listed before.
Here’s how it works
Microsoft has modified the Migration Assistant utility to run without logging the user off. But modifying the app caused it to crash due to a codesign failure. What the security researchers then did was to run Setup Assistant (the app that guides the user through the first setup of a Mac) in debug mode, so that it would ignore the fact that Migration Assistant had been modified and lacked a valid signature.

Since Setup Assistant was running in debug mode, the researchers could easily skip the steps of the setup process and jump straight to Migration Assistant. But even running in the macOS environment, this would still require having a disk to be restored and interaction with the interface.
To take the exploit even further, Microsoft has created a small 1GB Time Machine backup that could have malware on it. So the researchers created an AppleScript that automatically mounted this backup and interacted with the Migration Assistant interface without the user even noticing. As a result, the Mac would import the data from that malicious backup.
Should you be worried?
Luckily, you don’t have to worry if your Mac is running the latest version of macOS Ventura. That’s because Microsoft informed Apple about the exploit, which was fixed with the macOS 13.4 update – released on May 18 to the public. Apple thanked the Microsoft researchers on its security webpage.
If you haven’t updated your Mac yet, make sure you install the latest version of macOS as soon as possible by going to System Settings > General > Software Update.
Recommend
-
15
Bypass McAfee Application Control--Write&Read Protection 三好...
-
11
Use SCT to Bypass Application Whitelisting Protection 三好学生
-
71
PHP 7.1-7.3 disable_functions bypass This exploit utilises a use after free
-
18
How to bypass CloudFlare bot protection ?Several months ago I submitted what appeared to be a security flaw to CloudFalre’s bugbounty program. According to them, this is not a problem, it’s up to you to make up your own mi...
-
3
Bypass Cloudflare General Related to my Medium post: How to bypass Cloudflare bot protection Detailed operation
-
7
October 28, 2021 Microsoft finds new macOS vulnerability, Shrootless, that could bypass System Integrity Protection Microsoft has discovered a vulnerability that could allow an attacker to bypass...
-
12
Is It Difficult to Bypass Protection That Uses Big Data? ...
-
9
How to: Disable macOS System Integrity Protection Comments: Tags: WalkthroughMacOS
-
9
News Cybercriminals bypass Windows security with driver-vulnerability exploit Cro...
-
5
OpenAI revokes ChatGPT Bing integration as users exploit it to bypass paywalls...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK