A race condition in Apple’s userspace entitlement and code-signing checks allowed local attackers to bypass authorization in privileged IPC services and escalate to root. Project Zero documented the underlying weakness as racy validation tied to process identity, while a later public write-up showed the issue in practice in com.apple.appleseed.fbahelperd, Apple’s privileged Feedback Assistant XPC service, tracked as CVE-2019-8565.
The exploit abused PID reuse to impersonate a trusted client after the daemon validated the wrong process context, defeating entitlement checks that should have restricted access. Once inside the service, an attacker could invoke copyLogFiles: to copy arbitrary files through path traversal and chain additional helper behavior to achieve root code execution; Apple addressed the flaw in macOS 10.14.4 and iOS 12.2, and researchers said the bug reinforced that PID-based authorization in macOS IPC should be replaced with audit-token-based validation.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A public technical write-up described how PID reuse could bypass fbahelperd authorization, how path traversal in copyLogFiles: enabled arbitrary file copies, and how those primitives could be chained to root code execution. The post also stated that a proof of concept for CVE-2019-8565 was published publicly.
A Project Zero issue titled "MacOS/iOS userspace entitlement checking is racy" was published, documenting the broader PID-based entitlement checking race pattern affecting Apple user-space IPC authorization.
Apple addressed the local privilege escalation flaw in the privileged XPC service com.apple.appleseed.fbahelperd in macOS 10.14.4 and iOS 12.2. The fix also addressed the underlying trust issue discussed in the write-up for audit-token handling before those releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.