Microsoft has released details about a security vulnerability that was fixed with the macOS Sequia 15.2 update, released in December. The flaw could have been exploited by an attacker to bypass macOS's System Integrity Protection (SIP), which prevents unauthorized code execution.
Documented as CVE-2024-44243, the vulnerability involved the macOS Storage Kit daemon and its rights. According to Microsoft, Storage Kit “has numerous SIP bypass capabilities” that a hacker can exploit. The Sequoia 15.2 update security notes indicate that a configuration issue was the cause of the flaw:
Storage kit
- Available for: macOS Sequoia
- Impact: An application may be able to modify protected parts of the file system
- Description: A configuration issue has been resolved with additional restrictions.
- CVE-2024-44243: Mickey Jin (@patch1t), Jonathan Bar or (@yo_yo_yo_jbo) from Microsoft
SIP became part of macOS more than nine years ago, with the release of OS X El Capitan. When SIP is running, the Mac is often said to be in “rootless” mode and a majority of users can use SIP without it ever causing a problem. Chances are you don't even know you're using SIP. Some users need root access to their Mac and SIP can be disabled.
How to protect yourself from malware
Apple releases security patches through operating system updates, so it's important to install them as soon as possible. And as always, when downloading software, get it from trusted sources, like the App Store (which does security checks on its software) or directly from the developer. igamesnews has several guides to help you, including a guide on whether or not you need antivirus software, a list of Mac viruses, malware, and Trojans, and a comparison of Mac security software.



