MacOS "DirtyNIB" Vulnerability
ID: e7451d1b-4513-5ec9-ba79-d11ce2a230b3
STIX ID: report--e7451d1b-4513-5ec9-ba79-d11ce2a230b3
Feed Name: XPN Infosec Blog
Threat Score
## Executive summary This blog post details a macOS vulnerability (termed “DirtyNIB”) where modified NIB/XIB files in application bundles can be used to execute AppleScript and hijack application entitlements (e.g., Photos and Microphone) after Gatekeeper verification. The author provides PoCs against Pages and CarPlay Simulator, explains mitigations introduced in Ventura and Sonoma and workarounds, and states they reported the issue to Apple without a satisfactory resolution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
