Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

ELECTRONizing macOS Privacy - A New Weapon in Your Red Teaming Armory

Objective-See Foundation via YouTube

Overview

Discover how to bypass macOS privacy controls through Electron apps in this security conference talk from Objective-See Foundation. Learn about the vulnerabilities in macOS Transparency, Consent, and Control (TCC) framework that restricts access to sensitive resources like documents, camera, and microphone. Explore a new open-source tool that exploits Electron default configurations in popular apps like Microsoft Teams, Slack, and Discord to execute code and inherit their TCC permissions, even bypassing macOS Ventura App Protection. Gain insights into macOS privacy restrictions, their weaknesses, and practical red teaming techniques, while also understanding detection methods for blue teams. Principal Security Consultant Wojciech Reguła, known for creating iOS Security Suite and finding vulnerabilities in major tech companies, shares his expertise in Apple device security and demonstrates practical approaches to exploiting these security gaps.

Syllabus

#OBTS v6:0 "ELECTRONizing macOS Privacy - a New Weapon in Your Red Teaming Armory" - Wojciech Reguła

Taught by

Objective-See Foundation

Reviews

Start your review of ELECTRONizing macOS Privacy - A New Weapon in Your Red Teaming Armory

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.