logo

Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions

ID: 1ac90cd8-d49c-530b-8d4b-5e6cbb2bbfc2

STIX ID: report--1ac90cd8-d49c-530b-8d4b-5e6cbb2bbfc2

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2025-01-13

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence discloses CVE-2024-44243, a macOS System Integrity Protection (SIP) bypass where the storagekitd daemon can be induced to spawn third-party user-filesystem binaries (from /Library/Filesystems bundles), allowing an attacker with local root to load third-party kernel extensions and potentially install rootkits or evade security; Apple released a fix on 2024-12-11 and users are advised to update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.