Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines research on XPC services exposed by 29 macOS antivirus products, including client validation failures, runtime protection weaknesses, application control bypasses, and local privilege escalation. It concludes with recommendations for developers and users to improve XPC security.
Syllabus
Intro
whoami - Wojciech
whoami - Csaba
Intro to XPC
statistics
typical issues
No client validation in XPC server
Lack of /Broken runtime protections in XPC dient
Improper runtime protections verification in XPC server
MacKeeper
Intego Mac Security
Avast & AVG
ClamXAV (CVE-2020-26893)
Acronis
the client
the XPC service
secure sample
Shield.app
the future
Further resources
Taught by
nullcon