• Latest
  • Trending
PoC Exploit Code Released by Expert for macOS Sandbox Escape Flaw – Security Cases

PoC Exploit Code Released by Expert for macOS Sandbox Escape Flaw – Security Cases

23.11.2022
Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems

Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems

26.01.2023

Global Humic-Based Biostimulants Market Report 2022: High Development Costs of New Synthetic Crop Protection Products Drive Growth

26.01.2023
‘Cat p*** in a bottle’ – John Fury spits Prime as he tries KSI and Logan Paul’s drink for the first time and insists he prefers the brand backed by his son Tyson Fury

‘Cat p*** in a bottle’ – John Fury spits Prime as he tries KSI and Logan Paul’s drink for the first time and insists he prefers the brand backed by his son Tyson Fury

26.01.2023
Brighton ‘contacted’ over Tariq Lamptey as Sporting Lisbon defender offers eye loan as Pedro Porro closes in on Tottenham transfer

Tottenham set to sign Pedro Porro as Sporting Lisbon star Tariq Lamptey on loan as replacement

26.01.2023

Global Handwriting Recognition (HWR) Market Report 2022: With MyScript, Hanwang Technology, Nuance Communications, SELVAS AI &; Following

26.01.2023
Wolves agree a fee for Flamengo midfielder Joao Gomes, who was linked with Liverpool and Man United, after winning the tug of war against Lyon

Wolves agree a fee for Flamengo midfielder Joao Gomes, who was linked with Liverpool and Man United, after winning the tug of war against Lyon

26.01.2023

Alexandre & Baldwin Announces Reporting Information for 2022 Dividend Distributions

26.01.2023
Everything you need to know about Love Island Episode 10

Everything you need to know about Love Island Episode 10

26.01.2023
FirstFT: Hong Kong citizens facing Chinese crackdown can stay in US

FirstFT: Hong Kong citizens facing Chinese crackdown can stay in US

26.01.2023
The stocks that move the most after hours: Intel, Visa, Hasbro and more

The stocks that move the most after hours: Intel, Visa, Hasbro and more

26.01.2023
‘I said something wrong’ – UFC legend Rampage Jackson reveals he ‘went to see’ Joe Rogan and that’s why he was never on his podcast

‘I said something wrong’ – UFC legend Rampage Jackson reveals he ‘went to see’ Joe Rogan and that’s why he was never on his podcast

26.01.2023

FS Credit Opportunities Corp. (FSCO) declares distribution for February 2023

26.01.2023
Thursday, January 26, 2023
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » PoC Exploit Code Released by Expert for macOS Sandbox Escape Flaw – Security Cases

PoC Exploit Code Released by Expert for macOS Sandbox Escape Flaw – Security Cases

23/11/2022 22:50:13
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems

Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems

26.01.2023

Global Humic-Based Biostimulants Market Report 2022: High Development Costs of New Synthetic Crop Protection Products Drive Growth

26.01.2023

A researcher has released details and proof-of-concept (PoC) code for the high-severity macOS Sandbox escape vulnerability tracked as CVE-2022-26696.

SecuRing researcher Wojciech Reguła (@_r3ggi) has published technical details and proof-of-concept (PoC) code for a macOS sandbox escape vulnerability tracked as CVE-2022-26696 (CVSS score 7.8 ).

In a review published by Regula, the researcher observed that the problem is caused by a strange behavior he observed in a sandboxed macOS application that can launch any application that will not inherit the sandbox profile. from the main application.

According to ZDI, this vulnerability allows remote attackers to evade the sandbox on affected installations of Apple macOS. An attacker must first obtain the ability to execute low-privilege code on the target system in order to exploit this vulnerability.

“A sandboxed process may be able to circumvent sandbox restrictions.” reads the advisory published by Apple which fixed the flaw with better environment sanitization.

According to ZDI, a remote attacker can trigger the sandbox evasion flaw on vulnerable Apple macOS installations. ZDI pointed out that an attacker can only exploit the bug if they have first gained the ability to execute low-privilege code on the target system.

“This vulnerability allows remote attackers to evade the sandbox on affected installations of Apple macOS. An attacker must first gain the ability to execute low-privilege code on the target system in order to exploit this vulnerability. reads the report published by ZDI. “The specific flaw exists in the handling of XPC messages in the LaunchServices component. A crafted message can trigger the execution of a privileged operation. An attacker can exploit this vulnerability to elevate privileges and execute arbitrary code in the context of the current user.

The issue was reported to the vendor on December 22, 2021 and disclosed on August 15, 2022.

Regula focused its analysis on an Objective-C method of Terminal.app.

“+[TTApplication isRunningInInstallEnvironment] will return YES when the __OSINSTALL_ENVIRONMENT environment variable has been set. writes the expert. “So when Terminal.app starts, some of the environment variables weren’t cleared when +[TTApplication isRunningInInstallEnvironment] returned YES. Awesome, with a simple command injection I was able to run code in the Terminal.app context without a sandbox!

The expert was able to weaponize the flaw by embedding the exploit in a Word document and loading Mythic’s JXA payload.

“Running code in the Terminal.app context can be very dangerous because some TCC permissions may also already be granted.” Regula explained.

Reguła shared a PoC video that demonstrates how to weaponize a Word document to escape the sandbox and run code in the terminal.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(Security cases – hacking, macOS Sandbox Escape)



Share on




Related

Previous Post

Rams rule out Matthew Stafford for Week 12 vs. Chiefs as QB still in concussion protocol

Next Post

England ‘made a statement’ with six-goal display against Iran, says Jordan Pickford, who raves about ‘incredible’ Jude Bellingham and insists ‘We are here to win the World Cup’

Related Posts

Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems
Technology

Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems

26.01.2023
0

New and improved models lift more, last longer and are easier to use DALLAS, January 26, 2023 /PRNewswire/ -- NADA...

Read more

Global Humic-Based Biostimulants Market Report 2022: High Development Costs of New Synthetic Crop Protection Products Drive Growth

26.01.2023

Global Handwriting Recognition (HWR) Market Report 2022: With MyScript, Hanwang Technology, Nuance Communications, SELVAS AI &; Following

26.01.2023

Alexandre & Baldwin Announces Reporting Information for 2022 Dividend Distributions

26.01.2023

FS Credit Opportunities Corp. (FSCO) declares distribution for February 2023

26.01.2023

Pixelworks to Report Fourth Quarter and Fiscal Year 2022 Financial Results on February 9

26.01.2023
Load More
Next Post
England ‘made a statement’ with six-goal display against Iran, says Jordan Pickford, who raves about ‘incredible’ Jude Bellingham and insists ‘We are here to win the World Cup’

England 'made a statement' with six-goal display against Iran, says Jordan Pickford, who raves about 'incredible' Jude Bellingham and insists 'We are here to win the World Cup'

Recent Posts

  • Efficiently service any electric vehicle with the new BendPak Mobi-EVS EV & Powertrain Lift Systems
  • Global Humic-Based Biostimulants Market Report 2022: High Development Costs of New Synthetic Crop Protection Products Drive Growth
  • ‘Cat p*** in a bottle’ – John Fury spits Prime as he tries KSI and Logan Paul’s drink for the first time and insists he prefers the brand backed by his son Tyson Fury
  • Tottenham set to sign Pedro Porro as Sporting Lisbon star Tariq Lamptey on loan as replacement
  • Global Handwriting Recognition (HWR) Market Report 2022: With MyScript, Hanwang Technology, Nuance Communications, SELVAS AI &; Following

Archives

  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.