Apple Bug Allows Root Protections Bypass Without Physical Access
ID: 9a521fe1-d0d7-5d8b-8bc1-c2851785f452
STIX ID: report--9a521fe1-d0d7-5d8b-8bc1-c2851785f452
Feed Name: Dark Reading
Date Published: 2025-01-14
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Microsoft Threat Intelligence and others warn about CVE-2024-44243, a macOS System Integrity Protection (SIP) bypass patched by Apple (Dec 11). The flaw could allow attackers to install rootkits and persistent malware without physical access; defenders are advised to apply the patch, monitor processes with special entitlements, watch for unusual disk and privileged-user activity, control third-party kernel extensions, and use endpoint detection and least-privilege policies. The report also notes related macOS infostealer activity (Banshee) as an example of threats that can skirt protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
