Microsoft reports SIP-bypassing “Shrootless” vulnerability in macOS

 In apple, MacOS, microsoft, Tech, vulnerability

Microsoft reports SIP-bypassing “Shrootless” vulnerability in macOS

Serving the Technologist for more than a decade. IT news, reviews, and analysis.
The worm says, "I've got root!"

Enlarge / The worm says, “I’ve got root!” (credit: Andreus / Getty Images)

The Microsoft 365 Defender Research Team released a blog post yesterday describing a newly found macOS vulnerability that can abuse entitlement inheritance in macOS’s System Integrity Protection (SIP) to allow execution of arbitrary code with root-level privilege. The vulnerability is listed as CVE-2021-30892 and has been given the nickname “Shrootless.”

To explain how Shrootless works, we need to review how SIP functions. Introduced back in 2015 with OS X 10.11 El Capitan (and explained in detail on pages eight and nine of our review), SIP attempts to do away with an entire class of vulnerabilities (or at least neuter their effectiveness) by adding kernel-level protections against changing certain files on disk and certain processes in memory, even with root privilege. These protections are (more or less) inviolable unless one disables SIP, which cannot be done without rebooting into recovery mode and executing a terminal command.

The Shrootless exploit takes advantage of the fact that, while root privilege is no longer sufficient to change important system files, the kernel itself still can—and does—alter protected locations as needed. The most obvious example is when installing an application. Apple-signed application install packages have the ability to do things normally prohibited by SIP, and that’s where Shrootless slides in.

Read 5 remaining paragraphs | Comments

Exploit based on SIP entitlement inheritance was patched by Apple on October 26.

Recent Posts
Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Not readable? Change text. captcha txt