This issue was addressed with a new entitlement. This issue is fixed in macOS Monterey 12.3. An app may be able to spoof system notifications and UI.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/insidegui/CoreFollowUpAttack