macOS

macOS layers several of its own controls on top of a Unix base, so attacking a Mac is as much about defeating Apple's privacy, signing, and integrity frameworks as it is about classic Unix privilege escalation. The work is to move from a normal user to root, step past the controls that gate sensitive data and code execution, and read the secrets the system protects.

The local surface#

  • Privilege escalation: the Unix mechanisms (SUID, sudo, writable paths) plus macOS-specific service, helper-tool, and installer abuses.
  • TCC: bypassing Transparency, Consent, and Control, the framework that gates access to files, the camera, the microphone, and automation, to reach data without the user's approval.
  • Gatekeeper and code signing: defeating quarantine, notarization, and signature checks to run unsigned or untrusted code.
  • SIP and the sandbox: escaping the application sandbox and the boundaries System Integrity Protection enforces even on root.
  • Credential access: reading the login and system keychains and other credential stores.
  • Persistence: launch agents and daemons, login items, and configuration profiles.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more