Close Menu
The LinkxThe Linkx
  • Home
  • Technology
    • Gadgets
    • IoT
    • Mobile
    • Nanotechnology
    • Green Technology
  • Trending
  • Advertising
  • Social Media
    • Branding
    • Email Marketing
    • Video Marketing
  • Shop

Subscribe to Updates

Get the latest tech news from thelinkx.com about tech, gadgets and trendings.

Please enable JavaScript in your browser to complete this form.
Loading
What's Hot

This company could beat Apple and Qualcomm to the year’s most powerful…

May 20, 2025

GRI’s North American lead Matthew Rusk steps aside

May 20, 2025

Mitigating Risk in Construction – Connected World

May 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram Pinterest Vimeo
The LinkxThe Linkx
  • Home
  • Technology
    • Gadgets
    • IoT
    • Mobile
    • Nanotechnology
    • Green Technology
  • Trending
  • Advertising
  • Social Media
    • Branding
    • Email Marketing
    • Video Marketing
  • Shop
The LinkxThe Linkx
Home»Trending»Apple fixes macOS flaw that let attackers bypass system protections
Trending

Apple fixes macOS flaw that let attackers bypass system protections

Editor-In-ChiefBy Editor-In-ChiefJanuary 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Apple fixes macOS flaw that let attackers bypass system protections
Share
Facebook Twitter LinkedIn Pinterest Email


Update your Mac as soon as possible

Apple fixes macOS flaw that let attackers bypass system protections

A macOS vulnerability exposed Apple devices to severe security risks by bypassing System Integrity Protection, but a security patch has killed the exploit.

On January 13, 2025, Microsoft Threat Intelligence revealed a critical vulnerability in macOS — CVE-2024-44243 — that bypasses Apple’s System Integrity Protection (SIP) by exploiting third-party kernel extensions. This issue, now patched, could have allowed attackers to compromise macOS security at its core.

System Integrity Protection (SIP) is a macOS security feature designed to safeguard critical system files and processes. It restricts even users with administrative privileges from making changes that could compromise the operating system’s stability and security.

SIP protects sensitive system files, prevents arbitrary kernel code execution, and ensures apps can’t load unauthorized kernel drivers.

CVE-2024-44243 showed how attackers could bypass SIP protections by loading malicious third-party kernel extensions called rootkits. Rootkits grant unauthorized access, install persistent malware, bypass user permissions, and tamper with security mechanisms.

How CVE-2024-44243 works

The vulnerability relies on “entitlements,” which are special permissions embedded in macOS processes. These entitlements are important to SIP as they govern what a process can and cannot do.

Terminal output displaying storagekitd entitlements, including Apple code signing authorities and rootless-related keys like install, install.heritable, and volume.iSCPreboot.
Storagekitd and its entitlements. Image credit: Microsoft

Some processes have private entitlements reserved for essential system functions, such as debugging or file management.

Microsoft researchers discovered that attackers could exploit entitled processes — specifically the storagekitd daemon, which manages disk state through Apple’s Storage Kit framework. Since storagekitd inherits broad privileges, it could spawn child processes capable of bypassing SIP.

Attackers could insert their own kernel extensions to gain control over the operating system without detection using the daemon.

After identifying the vulnerability, Microsoft disclosed it to Apple under its Coordinated Vulnerability Disclosure (CVD) process. Apple addressed CVE-2024-44243 in its December 11, 2024 security updates, urging all users to update their Macs immediately.

How to protect your Mac

The best way to protect your Mac from this vulnerability is to make sure it’s running the latest macOS update. Apple fixed the issue in its December 11, 2024, security patches, so it’s crucial to update if you haven’t already.

To check, head to System Settings > General > Software Update and install any available updates.

If you’re using an older Mac that doesn’t support the latest macOS, keep an eye on Apple’s security updates for patches that might still apply to your system. It’s also a good idea to avoid installing third-party kernel extensions unless you’re sure they come from a trusted source.

You won’t have to worry about accidentally disabling SIP. It’s enabled by default in macOS, and disabling it requires deliberate steps using Terminal in Recovery Mode.



Source link

Adobe App Store Apple Apple Computer Apple Computer Inc. Apple Inc Apple TV attackers bypass fixes flaw Google i mac iBook iBook Store iMac Intel ios 9 ios9 iPad iPhone iphone 6 iphone 6s iPod classic iPod nano iPod shuffle iPod touch iTunes iTunes Store mac book mac os x mac osx Mac Pro MacBook Pro macOS Magic Mouse Magic Pad Microsoft Nokia Nvidia Protections Research in Motion RIM Samsung System
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleX’s Usage Data Suggests a Decline in Time Spent Throughout 2024
Next Article Hinge’s New AI Tool Wants to Help You Avoid Making a Bad Dating Profil…
Editor-In-Chief
  • Website

Related Posts

Gadgets

This company could beat Apple and Qualcomm to the year’s most powerful…

May 20, 2025
Mobile

16 things to know for Android developers at Google I/O 2025

May 20, 2025
Trending

Gemini (Live) coming to Google Chrome for Mac and Windows 

May 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

100+ TikTok Statistics Updated for December 2024

December 4, 202463 Views

Cisco Automation Developer Days 2025

February 10, 202516 Views

BenQ PD2730S Review – MacRumors

February 14, 202512 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from thelinkx.com about tech, gadgets and trendings.

Please enable JavaScript in your browser to complete this form.
Loading
About Us

Welcome to TheLinkX – your trusted source for everything tech and gadgets! We’re passionate about exploring the latest innovations, diving deep into emerging trends, and helping you find the best tech products to suit your needs. Our mission is simple: to make technology accessible, engaging, and inspiring for everyone, from tech enthusiasts to casual users.

Our Picks

This company could beat Apple and Qualcomm to the year’s most powerful…

May 20, 2025

GRI’s North American lead Matthew Rusk steps aside

May 20, 2025

Mitigating Risk in Construction – Connected World

May 20, 2025

Subscribe to Updates

Get the latest tech news from thelinkx.com about tech, gadgets and trendings.

Please enable JavaScript in your browser to complete this form.
Loading
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Thelinkx.All Rights Reserved Designed by Prince Ayaan

Type above and press Enter to search. Press Esc to cancel.