XCSSET
Vulnerability details
Advisory: SB2021052415 - Multiple vulnerabilities in Apple macOS Big Sur
Vulnerable component: macOS
CVE-ID: CVE-2021-30713
CVSSv3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C
CWE-ID: CWE-20 - Improper input validation
Description:
The vulnerability allows a local user to bypass Privacy preferences.
The vulnerability exists due to insufficient validation of user-supplied input within the TCC subsystem. A malicious application can bypass Privacy preferences and gain full disk access, perform screen recording or gain other permissions without requiring user's explicit consent.
Note, the vulnerability is being actively exploited in the wild by XCSSET malware.
External links:
https://support.apple.com/en-us/HT212529
https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/