An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/HadessCS/Awesome-Privilege-Escalation
- https://github.com/amanszpapaya/MacPer
- https://github.com/houjingyi233/macOS-iOS-system-security