A technical review of CVE-2018-4340 detailed how a Safari sandbox escape on macOS abused the MediaRemote framework and the com.apple.mediaremoted.xpc service to trigger the launch of arbitrary installed applications. The researcher said Safari could reach the Mach service and spoof a bundle identifier inside an MRNowPlayingPlayerPathProtobuf message, leading mediaremoted to invoke LaunchServices and open apps such as Calculator. The write-up said Apple later fully patched the MediaRemote issue after it was publicly presented.
The same research also described a separate Safari-reachable XPC service, com.apple.hiservices-xpcservice, that allegedly exposed methods capable of rebooting the system, reading arbitrary plist files, and revealing remote files in Finder. The author linked that behavior to an older macOS Gatekeeper bypass involving NFS shares, raising the possibility that a remotely hosted application could be registered with LaunchServices and then launched through the MediaRemote path, extending the impact from sandbox escape to potential Gatekeeper circumvention.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A 2020 technical write-up revisits CVE-2018-4340, detailing how Safari sandbox access to MediaRemote could launch arbitrary installed apps and describing a separate Safari-reachable HIServices XPC issue. The post also documents testing of a possible chain with the older Gatekeeper bypass on NFS shares.
The author states CVE-2018-4340 was originally found on macOS High Sierra 10.13.x about two years before the 2020 retrospective. The bug involved Safari sandbox access to com.apple.mediaremoted.xpc and spoofing a bundle identifier to launch installed applications.
The author says Apple eventually completely patched the MediaRemote vulnerability after the TyphoonCon presentation. The post contrasts this with the separate HIServices issue, for which no Apple advisory was published.
According to the author, the proof of concept for CVE-2018-4340 worked on all Mojave versions. Catalina later unintentionally broke part of the exploit chain.
The post references a historical Gatekeeper bypass on macOS versions earlier than 10.14.5 where applications launched from remote NFS shares lacked a quarantine flag. This behavior was later explored in connection with the HIServices and MediaRemote issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.