Red Team | Subverting macOS Apps and Security Controls

Red Team | Subverting macOS Apps and Security Controls

🎙 Carlos Garrido 👥 70K 📅 February 17, 2026 ⏱ 36 min 👁 177 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

macOS0-dayLPEXPCTCC

Summary

Carlos Garrido, Red Team Operations Leader at Pentraze Cybersecurity, presents at SANS Hack & Defend Summit 2025. The talk focuses on discovering and exploiting 0-day vulnerabilities in macOS applications, particularly local privilege escalation (LPE) vulnerabilities. He explains key macOS security mechanisms such as XPC, TCC, and Authorization Services, and demonstrates how they can be bypassed through implementation flaws. He covers four specific vulnerabilities: Acronis Image (TCC bypass via insecure XPC), Epson Web Installer (missing authentication), Nimble Commander (code signature validation bypass), and Mclean Linear (race condition via PID reuse). Each vulnerability is demonstrated with proof-of-concept code and real-world impact. He emphasizes that achieving root is not the end goal but a pivot for further exploitation. He recommends using audit tokens instead of PID for validation and suggests resources for further learning.

131 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into macOS security research, with real-world examples and demonstrations. The argumentation is solid, as each vulnerability is explained with technical details and proof-of-concept code. The speaker’s experience and the inclusion of multiple case studies strengthen the credibility. However, the talk is more of an expert opinion than a formal study, and some aspects could be more deeply explored.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references his own research and mentions resources like Brian Trace, EveryBit, and Jonathan Levin’s books. The title accurately reflects the content. The talk is well-structured and technically accurate, but as a conference presentation, it lacks formal citations and peer review. The demonstrations are convincing, but the audience is not provided with detailed source code or references for further verification.

139 words

Title / Content Match

The title accurately reflects the content, focusing on subverting macOS applications and security controls through 0-day vulnerabilities.

Quality & Reliability

7/10

The talk presents real-world vulnerabilities discovered by the speaker, with demonstrations and technical details. However, it is a conference presentation without peer review, and some claims lack in-depth verification.

Key Moments

Cited Sources

  • SANS Hack & Defend Summit 2025 — Presentation venue
  • Brian Trace — Mentioned as a researcher who discloses macOS vulnerabilities
  • EveryBit — Mentioned as a security researcher
  • Jonathan Levin — Author of macOS and iOS internals books

Concurring Sources

Contribution & Novelties

The talk provides a practical overview of macOS security weaknesses and exploitation techniques, with real-world examples. It highlights common pitfalls in third-party applications and offers actionable recommendations. For further exploration, consider the following:

73 words

Radar Profile

The radar profile shows high scores in quantity and technical level, indicating a dense and technical presentation. Quality is also high, but reliability is slightly lower due to the lack of formal citations and peer review.

Reliability 6/10

💬 No comments were provided.