• 34ºc, Sunny

Microsoft has discovered a new macOS vulnerability, CVE-2024-44243, that could allow attackers to install rootkits

On January 15, Microsoft Threat Intelligence discovered a new macOS vulnerability, CVE-2024-44243, which could allow attackers to bypass Apple System Integrity Protection (SIP) in macOS by loading third-party kernel extensions. SIP is a security technique that restricts the execution of actions that could compromise the integrity of the system; as such, SIP bypass affects the overall security of the operating system. Bypassing SIP can have serious consequences, such as increasing the likelihood of attackers and malicious software authors successfully installing rootkits, creating persistent malicious software, bypassing transparency, consent, and control (TCC), and expanding the attack surface for other technologies and vulnerabilities.