macos-security-bypass
macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.
By yaklang · 2,901 installs
npx skills add yaklang/hack-skills --skill macos-security-bypass
Source repository · Upstream listing
SKILL: macOS Security Bypass — Expert Attack Playbook
AI LOAD INSTRUCTION : Expert macOS security bypass techniques. Covers TCC bypass, Gatekeeper evasion, SIP restrictions, sandbox escape, and entitlement abuse. Base models miss version specific bypass nuances and protection interaction effects.
0. RELATED ROUTING
Before going deep, consider loading:
[macos process injection](../macos process injection/SKILL.md) when you need dylib injection, XPC exploitation, or Electron abuse after achieving initial access
[linux privilege escalation](../linux privilege escalation/SKILL.md) for Unix layer privesc techniques that also apply to macOS (SUID, cron, writable paths)
[linux security bypass](../linux security bypass/SKILL.md) for shared Unix security bypass concepts
Advanced Reference
Also load [TCC BYPASS MATRIX.md](./TCC BYPASS MATRIX.md) when you need:
Per macOS version TCC bypass mapping
Protection type specific techniques (Camera, Microphone, FDA, Automation)
MDM/configuration profile abuse patterns
1. TCC (TRANSPARENCY, CONSENT, CONTROL) OVERVIEW
TCC is macOS's permission framework controlling access to sensitive resources (camera, microphone, contacts, full disk access, etc.).
1.1 TCC Database Locations
Database Path Controls Protection
User level ~/Library/Application Support/com.apple.TCC/TCC.db Per user consent decisions SIP protected since Catalina
System level /Library/Application Support/com.apple.TCC/TCC.db System wide consent decisions SIP protected
MDM managed Via configuration profiles Push PPPC (Privacy Preferences Policy Control) Device management
1.2 TCC Bypass Categories
Category Mechanism Typical Prerequisite
FDA app exploitation Piggyback on apps already granted Full Disk Access Write access to FDA app's bundle or plugin dir
Direct DB modification Edit TCC.db to grant consent SIP disabled or FDA
Inherited permissions Child process inherits parent's TCC grants Code execution in context of FDA granted app
Automation abuse Apple Events / osascript to control TCC granted app Automation permission (lower bar than direct TCC)
Mounting tricks Mount a crafted disk image containing modified TCC.db Local access, pre Ventura
SQL injection in TCC Malformed bundle IDs triggering SQL injection in TCC subsystem CVE 2023 32364 and similar
1.3 Known TCC Bypass Patterns
Terminal / iTerm FDA inheritance : Terminal.app granted FDA → any command run inherits FDA → read any file.
Finder automation : Automate Finder (lower permission bar) to access files in protected locations.
System Preferences / System Settings injection : Inject into a process that already has TCC permissions by writing to its Application Scripts folder.
MDM profile abuse : PPPC profiles can pre approve TCC permissions. Rogue MDM enrollment or compromised MDM server → push PPPC payload.
2. GATEKEEPER BYPASS
Gatekeeper blocks unsigned or unnotarized apps from executing. Core enforcement depends on the com.apple.quarantine extended attribute.
2.1 Quarantine Attribute Removal
2.2 Bypass Techniques
Technique How It Works macOS Version
xattr d removal Remove quarantine before execution All (requires local access)
App translocation bypass Apps in certain locations skip translocation Pre Catalina
Archive tools that strip quarantine Some unarchiver apps don't propagate quarantine Varies by tool
Unsigned code in signed bundle Notarized app bundles with unsigned nested helpers Pre Ventura (CVE 2022 42821)
Safari auto extract + open Downloaded ZIP auto extracted, app opened before quarantine fully applied Safari specific, patched
ACL abuse com.apple.quarantine can be blocked by ACLs set before download Requires pre positioning
Disk image (DMG) tricks DMG mounted from network share may not carry quarantine Network share context
BOM (Bill of Materials) bypass Crafted BOM in pkg skips quarantine for extracted files CVE 2022 22616
2.3 Gatekeeper Check Flow
3. SIP (SYSTEM INTEGRITY PROTECTION)
SIP restricts root from modifying protected system locations, loading unsigned kernel extensions, and debugging system processes.
3.1 SIP Protected Locations
3.2 SIP Status & Configuration
3.3 Entitlements That Bypass SIP
Entitlement Effect
com.apple.rootless.install Write to SIP protected paths
com.apple.rootless.install.heritable Child processes inherit SIP bypass
com.apple.security.cs.allow unsigned executable memory JIT/unsigned code in memory
com.apple.private.security.clear library validation Load unsigned libraries
3.4 Historical SIP Bypasses
CVE macOS Technique
CVE 2021 30892 (Shrootless) Monterey pre 12.0.1 system installd + post install script in signed pkg
CVE 2022 22583 Monterey pre 12.2 packagekit + mount point manipulation
CVE 2022 46689 (MacDirtyCow) Ventura pre 13.1 Race condition on copy on write, overwrite SIP files
CVE 2023 32369 (Migraine) Ventura pre 13.4 Migration Assistant TCC/SIP bypass via systemmigrationd
CVE 2024 44243 Sequoia pre 15.2 StorageKit daemon exploitation
4. SANDBOX ESCAPE
macOS sandboxing (App Sandbox, via sandbox exec or entitlements) restricts app access to filesystem, network, and IPC.
4.1 Office Sandbox Escape Patterns
Vector Description
Open/Save dialog abuse User grants file access via dialog → macro reads/writes beyond sandbox
~/Library/LaunchAgents/ persistence Some sandbox profiles allow writing LaunchAgent plists
Login Items manipulation Add login item pointing to payload outside sandbox
Shared container exploitation Multiple apps sharing the same App Group container
4.2 IPC Based Escape
IPC Mechanism Escape Vector
XPC Services Connect to privileged XPC service with insufficient client validation
Mach Ports Obtain send right to privileged task port
Apple Events Automate unsandboxed app to perform actions
Distributed Notifications Signal unsandboxed helper to execute payload
Pasteboard Write payload to pasteboard, have unsandboxed app consume it
4.3 Browser Sandbox
Chromium: Multi process model, renderer is sandboxed, browser process is not
Safari: WebContent process sandboxed, parent Safari process has more privileges
Exploit chain: renderer RCE → sandbox escape (via IPC bug to browser process) → system access
5. CODE SIGNING & ENTITLEMENTS
5.1 Inspecting Signatures and Entitlements
5.2 Entitlement Abuse for Privilege Escalation
Entitlement Abuse Scenario
com.apple.security.cs.disable library validation Load attacker dylib into entitled process
com.apple.security.cs.allow dyld environment variables DYLD INSERT LIBRARIES injection
com.apple.security.get task allow Attach debugger, inject code
com.apple.security.cs.debugger Debug any process
com.apple.private.apfs.revert to snapshot Revert APFS snapshots, bypass modifications
5.3 Hardened Runtime Bypass
Hardened Runtime prevents: DYLD env vars, debugging, unsigned memory execution. Bypasses:
Find entitled apps that weaken Hardened Runtime ( disable library validation )
Exploit JIT entitled apps (browsers, VMs) for unsigned code execution
Use get task allow entitled debug builds left in production
5.4 Library Validation Bypass
Library validation ensures only Apple signed or same team signed dylibs load.
6. PERSISTENCE AFTER BYPASS
Method Location Survives Reboot Notes
LaunchAgent ~/Library/LaunchAgents/ Yes User level, runs at login
LaunchDaemon /Library/LaunchDaemons/ Yes Root level, runs at boot
Login Items ~/Library/Application Support/com.apple.backgroundtaskmanagementagent/ Yes Visible in System Settings
Cron crontab e Yes Often overlooked by defenders
Dylib hijack Writable dylib search path Yes Triggered when target app launches
Folder Action ~/Library/Scripts/Folder Action Scripts/ Yes Triggers on folder events
7. macOS SECURITY BYPASS DECISION TREE
8. QUICK REFERENCE: TOOL COMMANDS