logo

Apple Bug Allows Root Protections Bypass Without Physical Access

ID: 9a521fe1-d0d7-5d8b-8bc1-c2851785f452

STIX ID: report--9a521fe1-d0d7-5d8b-8bc1-c2851785f452

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-01-14

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Microsoft Threat Intelligence and others warn about CVE-2024-44243, a macOS System Integrity Protection (SIP) bypass patched by Apple (Dec 11). The flaw could allow attackers to install rootkits and persistent malware without physical access; defenders are advised to apply the patch, monitor processes with special entitlements, watch for unusual disk and privileged-user activity, control third-party kernel extensions, and use endpoint detection and least-privilege policies. The report also notes related macOS infostealer activity (Banshee) as an example of threats that can skirt protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.