3 ms·
That's the root of the issue. The service is meant to be used by a system component but didn't or couldn't check whether that was actually true and the failure
by pilif 4y ago
That's the root of the issue. The service is meant to be used by a system component but didn't or couldn't check whether that was actually true and the failure to check properly was overlooked in the security review.
There's some history of similar problems where functionality offered by a privileged library was exposed to non-privileged users.
This isn't an apple-only issue though - before this system-level of authorization, there was suid binaries which could be abused because they didn't perform proper checking of user input.