This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/HadessCS/Awesome-Privilege-Escalation
- https://github.com/Jymit/macos-notes
- https://github.com/amanszpapaya/MacPer
- https://github.com/houjingyi233/macOS-iOS-system-security