A proof-of-concept (PoC) exploit code for a critical vulnerability in macOS, identified as CVE-2024-54527 has been disclosed.
This vulnerability allows attackers to bypass the Transparency, Consent, and Control (TCC) protection mechanism, potentially granting unauthorized access to sensitive user data.
The vulnerability, which affects versions of macOS prior to Sonoma 14.0, exists in the XPC service located at /System/Library/Frameworks/MediaLibrary.framework/Versions/A/XPCServices/com.apple.MediaLibraryService.xpc. This service possesses powerful TCC entitlements, including “com.apple.private.tcc.manager” and “com.apple.private.tcc.allow”.
According to researcher the exploit takes advantage of the fact that the vulnerable XPC service is neither signed with Hardened Runtime nor Library Validation. An attacker can exploit this by:
The researcher who discovered the vulnerability has uploaded the exploit code, demonstrating the severity of the issue.
This TCC bypass could allow malicious actors to:
Apple has addressed this vulnerability in macOS Sonoma 14.0 and later versions. The fix involves a new security mitigation in the AppleMobileFileIntegrity.kext, called “enforceTCCEntitlementHardening”.
This mitigation enforces stricter controls on processes with specific TCC-related entitlements:
Users and administrators are strongly advised to:
While Apple has patched this specific issue, it highlights the importance of continuous security updates and the potential risks associated with powerful system services.
As the details of this vulnerability are now public, it’s crucial for users to stay vigilant and keep their systems up-to-date to protect against potential exploits based on this and similar vulnerabilities.
ANY.RUN Threat Intelligence Lookup - Extract Millions of IOC's for Interactive Malware Analysis: Try for Free
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…