We Need To Talk About MACL
ID: c1a76d13-567f-5725-b473-169f02558c84
STIX ID: report--c1a76d13-567f-5725-b473-169f02558c84
Feed Name: XPN Infosec Blog
Threat Score
This blog post reverse-engineers macOS User-Intent and the com.apple.macl attribute, explains how sandbox extension tokens are issued and consumed by Sandbox.kext, and discloses CVE-2020-9968 — a vulnerability allowing a TCC privacy bypass by applying MACL entries (demonstrated via a chroot-based proof-of-concept). The author details the internals, PoC steps, impact, and confirms Apple patched the issue in macOS 10.15.6 (and equivalent iOS/watchOS/tvOS releases).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
