HomeSecurityVulnerability in macOS allows disabling of protection tools

Vulnerability in macOS allows disabling of protection tools

A new macOS has raised concerns in the cybersecurity community, as it could allow ordinary users of a system to disable critical protection tools without administrator privileges. The findings come from security firm XM Cyber, which revealed that the technique exploits the way Apple's operating system handles certain trusted communications between applications.

macOS vulnerability

Although the attack is not carried out remotely and assumes that the attacker has already gained access to a user account on the Mac, experts warn that this scenario is quite common in modern cyberattacks. Once an attacker gains initial access, they often attempt to neutralize monitoring and protection systems in order to move unhindered within the corporate network.

See also: Sploitlight vulnerability in macOS allows theft of personal data

How the new technique works

According to XM Cyber, the method exploits macOS' XPC communication framework, which is used to exchange data and commands between applications and system services.

The researchers found that when a user runs a legitimate, digitally signed app, macOS temporarily stores a kind of “trust fingerprint.” An attacker can then modify specific parts of the app and insert malicious code, while maintaining the trust relationship that has already been established.

The result is that the attacker can perform privileged XPC operations, which under normal circumstances are reserved exclusively for trusted software components and not for a standard user account.

Successfully tested on popular security tools

XM Cyber ​​revealed that it was able to successfully implement the technique on two well-known enterprise security platforms: CrowdStrike Falcon and Kandji.

In the case of Falcon, the researchers were able to disable the protection sensor from a simple user account. Similarly, in Kandji, they were able to protection mechanisms uninstall and disable endpoint security features.

What is particularly worrying is that these attacks did not require exploiting the operating system kernel or bypassing System Integrity Protection (SIP), one of macOS's key security mechanisms.

Kandji has already released a patch and has listed the vulnerability as CVE-2026-39118 . Apple has not yet issued an official advisory on the research findings .

“This technique exploits a vulnerability in macOS, but CrowdStrike’s Falcon sensor already has the capabilities to detect and prevent this technique,” ​​a CrowdStrike spokesperson said.

See also: Docker vulnerability allows MacOS users to download container images

Vulnerability in macOS allows disabling of protection tools

Why the issue particularly concerns businesses

In recent years, Mac computers have gained an increasing presence in business environments. Many companies choose the Apple ecosystem because of the stability and strong security mechanisms it offers.

However, tools like CrowdStrike Falcon and Kandji are often the last line of defense between a compromised user account and access to critical corporate data. If an attacker can defeat these layers of protection without administrator privileges, they gain a significant strategic advantage.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Experts believe that this research highlights a broader design problem. Many applications rely primarily on checks digital signature to determine whether a request is trustworthy. However, as XM Cyber's findings show, this approach may no longer be sufficient against modern attack techniques.

See also: New vulnerability in Microsoft Edge allows bypass of security mechanisms

Vulnerability in macOS allows disabling of protection tools

How can users be protected?

Although the method requires initial access to a user account, organizations are urged to beef up their defenses. Using strong passwords, authentication multi-factor , and keeping macOS and security applications can significantly reduce the risk.

At the same time, corporate system administrators should closely monitor software vendor guidelines and promptly apply available fixes.

XM Cyber ​​plans to demonstrate the technique in detail at Black Hat Arsenal in Las Vegas in August, where it will also showcase its open-source tool XPC Hunter. The case is a reminder that even mature and theoretically secure platforms like macOS can present unexpected attack surfaces when trust mechanisms between applications are not verified with sufficient rigor.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS