4 ms·
Demo shows root shell. So an attacker could simply install a RAT into /Library/LaunchDaemons and it's permanent.
by jpillora 6y ago
Demo shows root shell. So an attacker could simply install a RAT into /Library/LaunchDaemons and it's permanent.
- mrarm 6y agoIt's not that easy since the T2 chip runs a derivative of iOS which requires codesigning. The only problem is that the T2 rarely reboots which means that erasing any modifications from it might be difficult (as far as I am aware long pressing the power button for 10 seconds should be enough to reset both the T2 and Intel though). It is impossible to untethered persist a modified version of MacEFI without another exploit on the T2 since it has to be signed by Apple and the signature is properly checked.
- saagarjha 6y ago> It's not that easy since the T2 chip runs a derivative of iOS which requires codesigning. I mean, you can just ad-hoc sign?