This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to modify protected parts of the file system.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/fardeen-ahmed/Bug-bounty-Writeups
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/insecrez/Bug-bounty-Writeups
- https://github.com/jhftss/POC