CVE Tools

Apple's MacOS Gap Lets Users Disable Security Tools

Dark ReadingBy Jai Vijayan

ResearchmacOSCrowdStrike Falcon

Our summary

Researchers from XM Cyber reported a macOS privilege-escalation technique that lets a non-administrator disable enterprise security tooling by impersonating trusted application components, leveraging how macOS caches and reuses application trust data (CDHash). The reported impact includes CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM), both of which can be neutralized without kernel exploits or triggering alerts. Kandji has released an updated Agent to address the issue tracked as CVE-2026-39118, underscoring why organizations should urgently review macOS XPC-based security products for mitigations.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store