Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installation
A now-patched security flaw in Apple macOS has been made public by Microsoft. If it had been successfully exploited, it could have enabled an attacker operating as "root" to get around System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions.
The medium-severity issue, CVE-2024-44243 (CVSS score: 5.5), was fixed by Apple in macOS Sequoia 15.2, which was made available last month. According to the iPhone manufacturer, it's a "configuration issue" that could allow a malicious program to alter file system components that are secured.
The Microsoft Threat Intelligence team's Jonathan Bar Or stated that circumventing SIP could have detrimental effects, including making it more likely for attackers and malware developers to install ro...


