logo

DER Entitlements: The (Brief) Return of the Psychic Paper

ID: cc747fa4-60dd-5e4a-9b35-b46a16187f7f

STIX ID: report--cc747fa4-60dd-5e4a-9b35-b46a16187f7f

Feed Name: Google Project Zero

Threat Score
60/100

Date Published: 2023-01-12

Date Updated: 2026-04-27

Author: Google Project Zero

...
...

Project Zero researcher Ivan Fratric describes CVE-2022-42855: a flaw in Apple’s libCoreEntitlements DER parsing that permitted crafted DER-encoded entitlements to be ‘‘hidden’’ from provisioning-profile subset checks but still exposed to kernel entitlement queries, enabling privilege checks bypass (potentially useful for jailbreaks or unauthorized kext requests). The report explains the parsing differences, proof-of-concept tooling, exploitation paths, mitigation timeline, and that Apple patched the issue in December 2022.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.