IOHIDeous macOS Kernel Exploit
A vulnerability affecting the IOHIDFamily driver class used in Apple's macOS operating system may allow an unauthorised user to gain administration rights to the kernel.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability affecting the IOHIDFamily driver class used in Apple's macOS operating system may allow an unauthorised user to gain administration rights to the kernel.
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation requires local access to a system already and can only be triggered by forcing a log out operation. This can be done either by convincing a user to perform a log out or during a shutdown or reboot.
This vulnerability also allows both Apple Mobile File Integrity and System Integrity Protection security features to be disabled, reducing the protection against further malware infection
Remediation steps
Last edited: 18 January 2022 9:16 am