Apple Disk-O Party - Vulnerabilities in macOS Disk Management Systems
BSides Budapest IT Security Conference via YouTube
2,000+ Free Courses with Certificates: Coding, AI, SQL, and More
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore four critical disk-related vulnerabilities in Apple systems through this comprehensive security conference talk from BSides Budapest 2025. Dive deep into the workings of the diskarbitrationd system daemon, examining its preventive measures before uncovering sandbox escape and full TCC (Transparency, Consent, and Control) bypass vulnerabilities that impact this crucial system component. Learn about diskutil and storagekitd tools, understanding their functions and potential security implications, then discover multiple vulnerabilities including additional TCC bypasses and privilege escalation techniques. Examine how Disk Utility, diskutil's more powerful counterpart, can be exploited to escalate privileges from admin to root when GUI access is available, particularly relevant for scenarios involving unattended workstations. Gain practical insights into Apple's disk management security architecture and the various attack vectors that can compromise system integrity through disk-related services and utilities.
Syllabus
Apple Disk-O Party #BSidesBUD2025
Taught by
BSides Budapest IT Security Conference