CVE-2024-24787 is an argument-injection vulnerability in the Go toolchain on Darwin. When building a Go module containing CGO code, an attacker-controlled #cgo LDFLAGS directive can supply the Apple linker’s -lto_library option. The Apple version of ld may load the specified LTO library during linking, causing attacker-controlled code to execute in the security context of the user or automation process running the Go build.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-24787, a vulnerability in the Go CGO build process on macOS (Darwin) when using the Apple linker (ld). The exploit demonstrates that by specifying a malicious dynamic library via the '-lto_library' flag in a '#cgo LDFLAGS' directive, arbitrary code can be executed during the build process. The repository contains a Go file (poc.go) that triggers the loading of a malicious dynamic library, and an Objective-C file (malicious.m) that, when compiled as a dynamic library, executes code to launch Calculator.app. The exploit is local and requires the victim to build the Go module, at which point the malicious code is executed. The repository structure is minimal, with clear separation between the Go trigger and the malicious payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.