Skip to main content

IOHIDeous macOS Kernel Exploit

A vulnerability affecting the IOHIDFamily driver class used in Apple's macOS operating system may allow an unauthorised user to gain administration rights to the kernel.

Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability affecting the IOHIDFamily driver class used in Apple's macOS operating system may allow an unauthorised user to gain administration rights to the kernel.


Affected platforms

The following platforms are known to be affected:

Threat details

Exploitation requires local access to a system already and can only be triggered by forcing a log out operation. This can be done either by convincing a user to perform a log out or during a shutdown or reboot.

This vulnerability also allows both Apple Mobile File Integrity and System Integrity Protection security features to be disabled, reducing the protection against further malware infection


Remediation steps

Type Step

This vulnerability has been patched in macOS High Sierra 10.13.2. However, the researcher who discovered the flaw suggest it would be trivial to re-engineer the exploit code to work on this version as well.

As this bug already requires local access or a previously compromised target system, users are reminded to practice good security and data hygiene.


Last edited: 18 January 2022 9:16 am