Apple disclosed security fixes in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, and Security Update 2019-002 Sierra that addressed local privilege-escalation flaws in Time Machine diagnostic components. Public research later detailed a command injection bug, tracked as CVE-2019-8513, affecting macOS 10.12.x through 10.14.3, where a local user could abuse the timemachinehelper XPC service and the tmdiagnose utility to execute arbitrary shell commands as root.
The exploit reportedly worked by crafting a mounted disk image label so shell metacharacters were injected into a command built from diskutil output, ultimately yielding a root shell after diagnostic tasks completed. The same research also described a related arbitrary file overwrite issue in XPC helpers, assigned CVE-2019-8530, and noted it could previously be chained with an older sudo timestamp weakness; the findings echoed earlier public work on browser-to-system compromise and underscored how trusted macOS helper services could be leveraged for full system takeover.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CodeColorist published a detailed writeup of the patched Time Machine command injection flaw, explaining how a crafted disk image label could trigger root command execution through timemachinehelper and tmdiagnose. The post also discussed the related arbitrary file overwrite issue tracked as CVE-2019-8530 and its prior exploitability with an older sudo timestamp flaw.
Apple released macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, and Security Update 2019-002 Sierra, addressing CVE-2019-8513 and CVE-2019-8530. Apple said the issues were fixed with improved checks and credited CodeColorist of Ant-Financial LightYear Labs.
A Black Hat USA 2016 paper by Samuel Groß and Niklas Baumstark documented exploitation techniques for escalating from a browser compromise to full system compromise on macOS. The later Time Machine vulnerability writeup references this prior research context.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
support.apple.com
Open sourcecodecolor.ist
Open sourceblackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.