The first paragraph in the “Root Cause” section explains: that binary has access to a service that’s allowed to bypass SIP restrictions.
It’s required to have those capabilities because this is what’s used by Apple to install their OS updates
It’s required to have those capabilities because this is what’s used by Apple to install their OS updates
Do all that entitlement dance all across the OS, sign the bootloader and ensure execution integrity up to the kernel and then do this.
sudo is bad, but it is not worse.
Like SELinux, you are not supposed to be able to disable without reboot.
There's some history of similar problems where functionality offered by a privileged library was exposed to non-privileged users.
This isn't an apple-only issue though - before this system-level of authorization, there was suid binaries which could be abused because they didn't perform proper checking of user input.