macos-security-bypass

macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.

By yaklang · 2,901 installs

npx skills add yaklang/hack-skills --skill macos-security-bypass

Source repository · Upstream listing

SKILL: macOS Security Bypass — Expert Attack Playbook AI LOAD INSTRUCTION : Expert macOS security bypass techniques. Covers TCC bypass, Gatekeeper evasion, SIP restrictions, sandbox escape, and entitlement abuse. Base models miss version specific bypass nuances and protection interaction effects. 0. RELATED ROUTING Before going deep, consider loading: [macos process injection](../macos process injection/SKILL.md) when you need dylib injection, XPC exploitation, or Electron abuse after achieving initial access [linux privilege escalation](../linux privilege escalation/SKILL.md) for Unix layer privesc techniques that also apply to macOS (SUID, cron, writable paths) [linux security bypass](../linux security bypass/SKILL.md) for shared Unix security bypass concepts Advanced Reference Also load [TCC BYPASS MATRIX.md](./TCC BYPASS MATRIX.md) when you need: Per macOS version TCC bypass mapping Protection type specific techniques (Camera, Microphone, FDA, Automation) MDM/configuration profile abuse patterns 1. TCC (TRANSPARENCY, CONSENT, CONTROL) OVERVIEW TCC is macOS's permission framework controlling access to sensitive resources (camera, microphone, contacts, full disk access, etc.). 1.1 TCC Database Locations Database Path Controls Protection User level ~/Library/Application Support/com.apple.TCC/TCC.db Per user consent decisions SIP protected since Catalina System level /Library/Application Support/com.apple.TCC/TCC.db System wide consent decisions SIP protected MDM managed Via configuration profiles Push PPPC (Privacy Preferences Policy Control) Device management 1.2 TCC Bypass Categories Category Mechanism Typical Prerequisite FDA app exploitation Piggyback on apps already granted Full Disk Access Write access to FDA app's bundle or plugin dir Direct DB modification Edit TCC.db to grant consent SIP disabled or FDA Inherited permissions Child process inherits parent's TCC grants Code execution in context of FDA granted app Automation abuse Apple Events / osascript to control TCC granted app Automation permission (lower bar than direct TCC) Mounting tricks Mount a crafted disk image containing modified TCC.db Local access, pre Ventura SQL injection in TCC Malformed bundle IDs triggering SQL injection in TCC subsystem CVE 2023 32364 and similar 1.3 Known TCC Bypass Patterns Terminal / iTerm FDA inheritance : Terminal.app granted FDA → any command run inherits FDA → read any file. Finder automation : Automate Finder (lower permission bar) to access files in protected locations. System Preferences / System Settings injection : Inject into a process that already has TCC permissions by writing to its Application Scripts folder. MDM profile abuse : PPPC profiles can pre approve TCC permissions. Rogue MDM enrollment or compromised MDM server → push PPPC payload. 2. GATEKEEPER BYPASS Gatekeeper blocks unsigned or unnotarized apps from executing. Core enforcement depends on the com.apple.quarantine extended attribute. 2.1 Quarantine Attribute Removal 2.2 Bypass Techniques Technique How It Works macOS Version xattr d removal Remove quarantine before execution All (requires local access) App translocation bypass Apps in certain locations skip translocation Pre Catalina Archive tools that strip quarantine Some unarchiver apps don't propagate quarantine Varies by tool Unsigned code in signed bundle Notarized app bundles with unsigned nested helpers Pre Ventura (CVE 2022 42821) Safari auto extract + open Downloaded ZIP auto extracted, app opened before quarantine fully applied Safari specific, patched ACL abuse com.apple.quarantine can be blocked by ACLs set before download Requires pre positioning Disk image (DMG) tricks DMG mounted from network share may not carry quarantine Network share context BOM (Bill of Materials) bypass Crafted BOM in pkg skips quarantine for extracted files CVE 2022 22616 2.3 Gatekeeper Check Flow 3. SIP (SYSTEM INTEGRITY PROTECTION) SIP restricts root from modifying protected system locations, loading unsigned kernel extensions, and debugging system processes. 3.1 SIP Protected Locations 3.2 SIP Status & Configuration 3.3 Entitlements That Bypass SIP Entitlement Effect com.apple.rootless.install Write to SIP protected paths com.apple.rootless.install.heritable Child processes inherit SIP bypass com.apple.security.cs.allow unsigned executable memory JIT/unsigned code in memory com.apple.private.security.clear library validation Load unsigned libraries 3.4 Historical SIP Bypasses CVE macOS Technique CVE 2021 30892 (Shrootless) Monterey pre 12.0.1 system installd + post install script in signed pkg CVE 2022 22583 Monterey pre 12.2 packagekit + mount point manipulation CVE 2022 46689 (MacDirtyCow) Ventura pre 13.1 Race condition on copy on write, overwrite SIP files CVE 2023 32369 (Migraine) Ventura pre 13.4 Migration Assistant TCC/SIP bypass via systemmigrationd CVE 2024 44243 Sequoia pre 15.2 StorageKit daemon exploitation 4. SANDBOX ESCAPE macOS sandboxing (App Sandbox, via sandbox exec or entitlements) restricts app access to filesystem, network, and IPC. 4.1 Office Sandbox Escape Patterns Vector Description Open/Save dialog abuse User grants file access via dialog → macro reads/writes beyond sandbox ~/Library/LaunchAgents/ persistence Some sandbox profiles allow writing LaunchAgent plists Login Items manipulation Add login item pointing to payload outside sandbox Shared container exploitation Multiple apps sharing the same App Group container 4.2 IPC Based Escape IPC Mechanism Escape Vector XPC Services Connect to privileged XPC service with insufficient client validation Mach Ports Obtain send right to privileged task port Apple Events Automate unsandboxed app to perform actions Distributed Notifications Signal unsandboxed helper to execute payload Pasteboard Write payload to pasteboard, have unsandboxed app consume it 4.3 Browser Sandbox Chromium: Multi process model, renderer is sandboxed, browser process is not Safari: WebContent process sandboxed, parent Safari process has more privileges Exploit chain: renderer RCE → sandbox escape (via IPC bug to browser process) → system access 5. CODE SIGNING & ENTITLEMENTS 5.1 Inspecting Signatures and Entitlements 5.2 Entitlement Abuse for Privilege Escalation Entitlement Abuse Scenario com.apple.security.cs.disable library validation Load attacker dylib into entitled process com.apple.security.cs.allow dyld environment variables DYLD INSERT LIBRARIES injection com.apple.security.get task allow Attach debugger, inject code com.apple.security.cs.debugger Debug any process com.apple.private.apfs.revert to snapshot Revert APFS snapshots, bypass modifications 5.3 Hardened Runtime Bypass Hardened Runtime prevents: DYLD env vars, debugging, unsigned memory execution. Bypasses: Find entitled apps that weaken Hardened Runtime ( disable library validation ) Exploit JIT entitled apps (browsers, VMs) for unsigned code execution Use get task allow entitled debug builds left in production 5.4 Library Validation Bypass Library validation ensures only Apple signed or same team signed dylibs load. 6. PERSISTENCE AFTER BYPASS Method Location Survives Reboot Notes LaunchAgent ~/Library/LaunchAgents/ Yes User level, runs at login LaunchDaemon /Library/LaunchDaemons/ Yes Root level, runs at boot Login Items ~/Library/Application Support/com.apple.backgroundtaskmanagementagent/ Yes Visible in System Settings Cron crontab e Yes Often overlooked by defenders Dylib hijack Writable dylib search path Yes Triggered when target app launches Folder Action ~/Library/Scripts/Folder Action Scripts/ Yes Triggers on folder events 7. macOS SECURITY BYPASS DECISION TREE 8. QUICK REFERENCE: TOOL COMMANDS