Research macOS privilege-escalation Apple web-app
macOS Weaknesses Chained to Silently Disable Endpoint Security Agents
CVE Tools coverage
XM Cyber demonstrated an attack on macOS in which a non-administrative user can silently disable enterprise endpoint security components, including EDR and MDM agents, without kernel exploits or triggering alerts. The technique chained abuse of weakly validated XPC connections with malicious payload injection into Interface Builder (NIB) files, and it was successfully demonstrated against CrowdStrike Falcon Sensor and Kandji MDM; CrowdStrike Falcon Sensor was fully unloaded from a standard account, while Kandji MDM was permanently deactivated. Kandji patched the issue and assigned CVE-2026-39118, underscoring the risk to environments that rely on these agents for detection and device management.