CVE Tools
Back to feed
Research macOS privilege-escalation CrowdStrike Falcon Apple

Apple's MacOS Gap Lets Users Disable Security Tools

Dark Reading·By Jai Vijayan··4 min read
CVE Tools coverage

Researchers from XM Cyber reported a macOS privilege-escalation technique that lets a non-administrator disable enterprise security tooling by impersonating trusted application components, leveraging how macOS caches and reuses application trust data (CDHash). The reported impact includes CrowdStrike Falcon Endpoint Detection and Response (EDR) and Kandji Mobile Device Management (MDM), both of which can be neutralized without kernel exploits or triggering alerts. Kandji has released an updated Agent to address the issue tracked as CVE-2026-39118, underscoring why organizations should urgently review macOS XPC-based security products for mitigations.