A researcher disclosed a three-bug macOS local privilege escalation chain that let an unprivileged user escalate to root, bypass System Integrity Protection (SIP), and ultimately achieve kernel code execution on systems before macOS 10.15.5. The first flaw was in authd, where Authorization Services trusted entitlement data returned by SecCodeCopySigningInformation without first validating the caller’s code signature, allowing forged entitlements such as com.apple.private.AuthorizationServices to unlock privileged authorization rights.
The chain then abused Apple-signed package installation through PackageKit and a vulnerable post-install script in macOSPublicBetaAccessUtility.pkg to execute code as root under system_installd, inheriting the com.apple.rootless.install.heritable entitlement and bypassing SIP. A third flaw in kextutil used a race condition to swap a verified Apple-signed kernel extension staged in /Library/StagedExtensions/private before loading; use of the -interactive flag made the race reliable enough to load malicious kernel code. The bugs were reported to Apple in 2020, and Apple addressed the issues in macOS 10.15.6 and tvOS 13.4.5, including a change so SecCodeCopySigningInformation verifies signatures directly.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Before public disclosure, Apple shipped fixes for the reported vulnerabilities in macOS 10.15.6 and tvOS 13.4.5. Apple also mitigated the authd issue by changing SecCodeCopySigningInformation to verify signatures directly.
Neodyme publicly disclosed technical details of the three-bug 'Unauthd' chain, describing flaws in authd, PackageKit-related installation, and a kextutil race condition. The disclosure explained how the chain could achieve root access, bypass SIP, and load malicious kernel code on macOS versions earlier than 10.15.5.
Neodyme researcher Ilias reported a three-bug macOS exploit chain to Apple that enabled user-to-root escalation, a SIP bypass, and kernel code execution. The report was submitted on February 28, 2020.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
developer.apple.com
Open sourceneodyme.io
Open sourceopensource.apple.com
Open sourceopensource.apple.com
Open sourceopensource.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.