{"id":6914,"date":"2025-01-14T15:45:43","date_gmt":"2025-01-14T21:45:43","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/apple-bug-root-protections-bypass-physical-access"},"modified":"2025-01-14T15:45:43","modified_gmt":"2025-01-14T21:45:43","slug":"apple-bug-allows-root-protections-bypass-without-physical-access","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/14\/apple-bug-allows-root-protections-bypass-without-physical-access\/","title":{"rendered":"Apple Bug Allows Root Protections Bypass Without Physical Access"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfc9591d02ff5af0b\/6786ced1fd4f5b5f72a533e9\/apple_root_Andrey_Kryuchkov_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyber defenders are encouraged to ensure systems have been updated with the latest macOS patch, which includes a fix for a vulnerability that exposed the entire operating system to further compromise.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The bug, tracked under CVE-2024-44243, was patched in the Dec. 11 <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/121839\">Apple security update<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, according to analysis from Microsoft Threat Intelligence that was released this week. The vulnerability could allow adversaries to bypass the macOS System Integrity Protection (SIP) restrictions, which limit operations that are detrimental to a device&#8217;s security. Without SIP controls in place, a threat actor could install rootkits, drop persistent malware, and more, according to the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/01\/13\/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions\/\">Microsoft report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. More disturbing, threat actors don&#8217;t need physical access to pull off the cyberattack.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This exposes the entire operating system to deeper compromise without needing physical access, threatening sensitive data and system controls,&#8221; said Jason Soroko, senior fellow at Sectigo, in a statement.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Detecting Other Apple Bug Exploits\">Detecting Other Apple Bug Exploits<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to updating vulnerable macOS systems, experts suggest cyber defenders be on the lookout for suspicious behavior.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Teams should proactively monitor processes with special entitlements, as these can be exploited to bypass SIP,&#8221; said Mayuresh Dani, manager, security research, at Qualys, in a statement provided in reaction to the flaw. &#8220;The behavior of these processes in the environments should also be maintained.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Soroko also advised teams to monitor for unusual disk management activity, in addition to anomalous privileged user behavior, and to implement endpoint detection tools and controls for unsigned kernel extensions. Dani agreed that third-party kernel extensions should be managed with care to prevent these sorts of attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Third-party kernel extensions &#8220;should be enabled only when absolutely necessary and with strict monitoring guidelines,&#8221; Dani added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is just one of the recent cyberattacks that has found its way around Apple&#8217;s defenses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The macOS infostealer malware &#8220;Banshee&#8221; was recently observed <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/banshee-malware-steals-apple-encryption-macs\">skirting Apple&#8217;s antivirus protections,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> courtesy of a string encryption algorithm stolen from Apple. It&#8217;s up to cyber teams to have adequate protections in place to lock down their own environments.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Regular integrity checks, principle-of-least-privilege policies, and strict compliance with Apple&#8217;s security guidelines further reduce exposure to this critical threat,&#8221; Soroko added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This and other similar flaws are a demonstration of a lack of security between root users and the operating system, Lionel Litty, chief security architect at Menlo Security, explained in a statement. It&#8217;s also an example of the limitations of endpoint-based solutions, he added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While endpoint-based security solutions are attractive from a cost and usability perspective compared to off-device solutions such as [virtual desktop infrastructure], the constant stream of OS vulnerabilities that allow a local attacker to bypass OS integrity protection mechanisms shows that this is a risky gamble,&#8221; Litty said. &#8220;If your security controls involve installing an application on an unmanaged device and relying on this application protecting itself, you need to closely monitor this type of issue.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/apple-bug-root-protections-bypass-physical-access\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber defenders are encouraged to ensure systems have been updated<\/p>\n","protected":false},"author":12,"featured_media":6915,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6914","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/apple-bug-allows-root-protections-bypass-without-physical-access-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6914","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6914"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6914\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6915"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6914"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6914"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6914"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}