CVE Tools

macOS Weaknesses Chained to Silently Disable Endpoint Security Agents

SecurityWeekBy Eduard Kovacs

ResearchmacOS

Our summary

XM Cyber demonstrated an attack on macOS in which a non-administrative user can silently disable enterprise endpoint security components, including EDR and MDM agents, without kernel exploits or triggering alerts. The technique chained abuse of weakly validated XPC connections with malicious payload injection into Interface Builder (NIB) files, and it was successfully demonstrated against CrowdStrike Falcon Sensor and Kandji MDM; CrowdStrike Falcon Sensor was fully unloaded from a standard account, while Kandji MDM was permanently deactivated. Kandji patched the issue and assigned CVE-2026-39118, underscoring the risk to environments that rely on these agents for detection and device management.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store