macOS LPE via the .localized directory
theevilbit.github.io·2d
💣ZIP Vulnerabilities
Preview
Report Post

This blog is about a vulnerability on macOS which impacts every third party installer if they try to run a privileged command from within the application bundle.

This vulnerability has a very long history, and Apple never managed to properly fix it, and I never got a CVE only a note in the “Additional Recognition” section.

A Little History Link to heading

There is a very long history of this specific bug that I kept reporting to Apple since 2018 (7 years!!). This bug can be exploited when we install third party software on the system. Actually this was my very first vulnerability I submitted to Apple, and my very first macOS talk back in 2019, called [macOS - Getting root with benign AppStore apps](https://theevilbit.github.io/posts/getting_root_with_b…

Similar Posts

Loading similar posts...