If I'm right this bug:
- affects < 15.5
- allows app to be signed forever
- arbitrary entitlements
If you're on < 15.5 stay there
Quote Tweet
New blog post:
Get root on macOS 12.3.1: proof-of-concepts for @LinusHenze's CoreTrust and DriverKit bugs
worthdoingbadly.com/coretrust/
My proof-of-concepts for:
CVE-2022-26766: CoreTrust allows any root certificate
CVE-2022-26763: IOPCIDevice::_MemoryAccess not checking bounds at all
43
115
533




