UPDATE Researchers have uncovered a novel macOS privilege-escalation technique that allows a user with standard privileges to disable enterprise security tools and invoke privileged functions without administrator credentials. The technique exploits how macOS establishes and validates application trust information. It enables an attacker to impersonate trusted application components and silently perform actions that should only be available to privileged processes. Researchers at XM Cyber who developed the technique showed how an attacker could use it to disable CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM) without needing any administrator credentials or kernel exploits and without triggering any alert. According to XM Cyber, the issue potentially affects other macOS applications that provide privileged Cross-Process Communication (XPC) services and rely on Apple's CDHash, a cryptographic identifier for verifying an application's authenticity. "MacOS applications routinely expose privileged XPC services running as root — yet the trust boundaries protecting these interfaces are fundamentally flawed," said XM Cyber senior security researcher Hillel Pinto, in a report this week. XM Cyber has developed an open source large language model (LLM)-powered tool it named XPC Hunter to help security researchers look for exploitable macOS XPC privilege escalation vulnerabilities across other macOS applications. The company plans to re...
Apple's MacOS Gap Lets Users Disable Security Tools
Dark Reading
·Jai Vijayan
·Published Jun 24, 2026
·Updated
Affected Software
3 affected components
CrowdStrike Falcon Endpoint Detection and Response (EDR)
Kandji Kandji Mobile Device Management (MDM) / Kandji Agent
Apple macOS
Frequently Asked Questions
1
What is the main vulnerability discussed in the article?
The article highlights a privilege-escalation vulnerability in macOS that allows users to disable enterprise security tools.
2
How does this vulnerability affect security tools on macOS?
This vulnerability permits users with standard privileges to bypass security controls and invoke privileged functions without needing administrator credentials.
3
Which security products are specifically mentioned as being affected by this vulnerability?
The affected products include CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM) systems.
4
What type of attack is this vulnerability classified as?
This vulnerability is classified as a privilege-escalation attack.
5
When was this vulnerability publicly disclosed?
The vulnerability was disclosed on June 24, 2026.