A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra. Processing a maliciously crafted package may lead to arbitrary code execution.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fardeen-ahmed/Bug-bounty-Writeups
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/insecrez/Bug-bounty-Writeups