• News/
  • darkreading-20260624120000

Apple's MacOS Gap Lets Users Disable Security Tools

Dark Reading
·
Jai Vijayan
·
Published Jun 24, 2026
·
Updated

UPDATE Researchers have uncovered a novel macOS privilege-escalation technique that allows a user with standard privileges to disable enterprise security tools and invoke privileged functions without administrator credentials. The technique exploits how macOS establishes and validates application trust information. It enables an attacker to impersonate trusted application components and silently perform actions that should only be available to privileged processes. Researchers at XM Cyber who developed the technique showed how an attacker could use it to disable CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM) without needing any administrator credentials or kernel exploits and without triggering any alert. According to XM Cyber, the issue potentially affects other macOS applications that provide privileged Cross-Process Communication (XPC) services and rely on Apple's CDHash, a cryptographic identifier for verifying an application's authenticity. "MacOS applications routinely expose privileged XPC services running as root — yet the trust boundaries protecting these interfaces are fundamentally flawed," said XM Cyber senior security researcher Hillel Pinto, in a report this week. XM Cyber has developed an open source large language model (LLM)-powered tool it named XPC Hunter to help security researchers look for exploitable macOS XPC privilege escalation vulnerabilities across other macOS applications. The company plans to re...

Read full article

Affected Software

3 affected components
CrowdStrike Falcon Endpoint Detection and Response (EDR)
Kandji Kandji Mobile Device Management (MDM) / Kandji Agent
Apple macOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main vulnerability discussed in the article?

The article highlights a privilege-escalation vulnerability in macOS that allows users to disable enterprise security tools.

2

How does this vulnerability affect security tools on macOS?

This vulnerability permits users with standard privileges to bypass security controls and invoke privileged functions without needing administrator credentials.

3

Which security products are specifically mentioned as being affected by this vulnerability?

The affected products include CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM) systems.

4

What type of attack is this vulnerability classified as?

This vulnerability is classified as a privilege-escalation attack.

5

When was this vulnerability publicly disclosed?

The vulnerability was disclosed on June 24, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203