Apple Disk-O Party

No ratings

Presented at Black Hat Europe 2024 by

In this talk I will share the details about four different vulnerabilities all related to disks. We will start by understanding how the diskarbitrationd system daemon works, and what preventive measures it has. I will then go through sandbox escape and full TCC bypass vulnerabilities impacted by this daemon. Then we will move on to talk about diskutil, and storagekitd - what they are and what they can be used for. Once we are familiar with the tools, I will detail several vulnerabilities, including full TCC bypasses and privilege escalations. Finally, we will divert to diskutil's big brother, Disk Utility. There I will show how someone can use this to elevate privileges from admin to root if GUI access is available, for example in unattended workstations.