MacOS47 CVE-2026-28910: Breaking the macOS App Sandbox, TCC and Code Signing with Archive Utility
Mysk research details CVE-2026-28910 — a chain of three macOS design flaws that turns the built-in Archive Utility plus a single drag-and-drop…
MacOS47 Mysk research details CVE-2026-28910 — a chain of three macOS design flaws that turns the built-in Archive Utility plus a single drag-and-drop…
MacOS56 CVE-2024-32002 turns git clone --recursive into RCE on case-insensitive filesystems. A crafted submodule + symlink can plant a Git hook in .git…
MacOS26 A bug in macOS’s TCP stack causes networking to fail after about 49.7 days of uptime. A 32-bit timer overflow freezes the…
MacOS31 A macOS Recovery Mode Safari flaw allowed attackers to write arbitrary files to system partitions. By placing a malicious LaunchDaemon in /Library/LaunchDaemons,…
Apple Silicon46 The article analyzes the macOS secure boot chain on Apple Silicon, showing how Boot ROM, cryptographic verification, Secure Enclave, and staged bootloaders…
EDR26 The article examines how EDR agents monitor macOS and Linux systems by collecting telemetry from OS security frameworks, kernel interfaces, and tools…