by @Hored1971
29 Aug 2023

CVE-2023-26818 (Sandbox): MacOS TCC Bypass W/ telegram using DyLib Injection (Part 2)

by @Hored1971
29 Aug 2023

CVE-2023-26818 (Sandbox): MacOS TCC Bypass W/ telegram using DyLib Injection (Part 2)

CVEs

5.5 Medium Severity

Apps

Telegram
TelegramTelegram
11.12.6.0.*
11.12.5.0.*
11.12.4.0.*
11.12.3.0.*
11.11.4.0.*
11.11.3.0.*
11.11.2.0.*
10.9.51.*
11.9.4.0.*
11.9.3.0.*

Screenshots from the blog posts

images/cllu5qweb68631hoh6isz7uax.pngimages/cllu5qweb68631hoh6isz7uax.png

Summary

In 2nd part of the analysis for CVE-2023-26818, We discussing the app sandboxing in MacOS and show how to bypass it. To exploit the vulnerability.

Description

users/photos/clp1t8yez9ki21jlp8bw0ezvd.png

@Hored1971

129 posts

Security Researcher | Playing around the core of the 7 layers to build the Zero-Day Empire.

Total vcoins

191.3K

Badges

badges/images/cl1xi65zx02el0jms239bekpv.png

Malware Researcher

Social media links

Comments (0)