Critical SIP Bypass Vulnerabilities in macOS PackageKit.framework
jhftss.github.io
jhftss.github.io
Because many installs (heck, going to a page with invalid cert in Safari!) ask for an admins password to install, which gives escalated privileges up to root.
So they added a level that requires higher than root access.
With this vulnerability, someone typing their password could allow beyond root privileges.
That is my simplified parsing of things.
Note - I didn’t read the article. I’m not in security. But I did live with Dan Kaminsky for close to 5 years. RIP :/
In contrast, alternative OSes implementations of mandatory access control do have a role that can be accessed by the user.
Why is it such a bad vulnerability if it requires a sudo command?
Why would daemons be running as root in 2022? What does that anymore, especially on macOS?
It’s required to have those capabilities because this is what’s used by Apple to install their OS updates
Do all that entitlement dance all across the OS, sign the bootloader and ensure execution integrity up to the kernel and then do this.
There's some history of similar problems where functionality offered by a privileged library was exposed to non-privileged users.
This isn't an apple-only issue though - before this system-level of authorization, there was suid binaries which could be abused because they didn't perform proper checking of user input.
sudo is bad, but it is not worse.
Like SELinux, you are not supposed to be able to disable without reboot.