Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

June 27, 2026

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

June 27, 2026

The AI Shift That’s Redefining Threat Management

June 27, 2026
Facebook X (Twitter) Instagram
Saturday, June 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»macOS Flaw Lets Standard Users Disable EDR and MDM
News

macOS Flaw Lets Standard Users Disable EDR and MDM

Team-CWDBy Team-CWDJune 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A macOS privilege escalation technique that silently disables enterprise security tools from an ordinary user account has been disclosed, affecting major endpoint detection and response (EDR) and mobile device management (MDM) products.

New research from exposure management specialise XM Cyber found that a non-root user could abuse macOS’s trusted software verification to call privileged functions without authentication. 

The flaw lies in XPC, the service macOS apps use to communicate with their background processes, and XM Cyber said it affects many applications.

Turning Security Tools Against Themselves

Many macOS apps run a privileged helper as root and let their own signed components communicate with it via XPC. The helper trusts callers based on their code signature, known as a CDHash.

XM Cyber found that macOS keeps that trust cached after a signed app first runs. An attacker can launch a legitimate app, tamper with it to load a malicious interface file, then inherit its trusted status. From that trusted context, the code can call the helper’s most sensitive functions with no authentication.

XM Cyber said these included built-in methods to run commands or shut down apps and system extensions. An attacker can use them to make a security product disable or remove itself, bypassing its own tamper protection.

Because the technique abuses normal macOS behavior, the researchers said it leaves almost no forensic trace.

CrowdStrike Responds to Findings 

XM Cyber said it validated the technique against well-known endpoint tools. On CrowdStrike’s Falcon sensor, it fully unloaded the agent from a standard user account, killing detection, process monitoring and network visibility.

CrowdStrike has since added detection and prevention across supported macOS sensor versions. The firm also deactivated Kandji’s MDM agent, which has been fixed and assigned CVE-2026-39118.

“The technique exploits a macOS issue, and we have detections and preventions in place for the Falcon sensor,” a CrowdStrike spokesperson told Infosecurity Magazine.

The researcher behind the discovery, XM Cyber’s Hillel Pinto, also built an open-source tool, XPC Hunter, that scans installed macOS apps for the same weakness, and plans to present it at Black Hat US in August.

The attack needs an existing foothold, a standard local account, so XM Cyber framed it mainly as an insider or post-compromise threat.

Read more on attacks that disable security software: GentleKiller Framework Disables Victims’ Security Software

The fix is straightforward, XM Cyber said: developers should validate the caller’s identity during the XPC handshake, using checks Apple has offered since macOS 13, rather than trusting the cached signature. 

Pinto said organizations should treat the technique as “a major gap in modern endpoint security models.” With the named vendors patched, the wider risk lies in the many other macOS apps that have not closed it.

Update 25 June, 2.30PM: this story was updated to include CrowdStrike’s comment.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCrypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
Next Article DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
Team-CWD
  • Website

Related Posts

News

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

June 27, 2026
News

CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

June 27, 2026
News

The AI Shift That’s Redefining Threat Management

June 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Is it OK to let your children post selfies online?

February 17, 2026

What if your romantic AI chatbot can’t keep a secret?

November 18, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.