{"id":40621,"date":"2021-04-27T15:17:22","date_gmt":"2021-04-27T15:17:22","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32237\/Actively-Exploited-Mac-0-Day-Neutered-Core-OS-Defenses.html"},"modified":"2021-04-27T15:17:22","modified_gmt":"2021-04-27T15:17:22","slug":"actively-exploited-mac-0-day-neutered-core-os-defenses","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/","title":{"rendered":"Actively Exploited Mac 0-Day Neutered Core OS Defenses"},"content":{"rendered":"<figure class=\"intro-image intro-left\"><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/04\/malicious-code-800x534.jpeg\" alt=\"Actively exploited Mac 0-day neutered core OS security defenses\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Getty Images<\/div>\n<\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"><a title=\"50 posters participating\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-security-defenses\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">54<\/span> <span class=\"visually-hidden\"> with 50 posters participating<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p><!-- cache hit 1414:single\/related:5981df65860af9800f2c8a6fefde993d --><!-- empty --><\/p>\n<p>When Apple <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/04\/new-versions-of-macos-watchos-and-tvos-hit-supported-devices-today\/\">released the latest version 11.3 for macOS<\/a> on Monday, it didn&#8217;t just introduce support for new features and optimizations. More importantly, the company fixed a zero-day vulnerability that hackers were actively exploiting to install malware without triggering core Mac security mechanisms, some that were in place for more than a decade.<\/p>\n<p>Together, the defenses provide a comprehensive set of protections designed to prevent users from inadvertently installing malware on their Macs. While <a href=\"https:\/\/arstechnica.com\/civis\/viewtopic.php?p=38015043\">one-click<\/a> and even <a href=\"https:\/\/arstechnica.com\/gadgets\/2020\/12\/iphone-zero-click-wi-fi-exploit-is-one-of-the-most-breathtaking-hacks-ever\/\">zero-click<\/a> exploits rightfully get lots of attention, it\u2019s far more common to see trojanized apps that disguise malware as a game, update, or other desirable piece of software.<\/p>\n<h2>Protecting users from themselves<\/h2>\n<p>Apple engineers know that trojans represent a bigger threat to most Mac users than more sophisticated exploits that surreptitiously install malware with minimal or no interaction from users. So a core part of Mac security rests on three related mechanisms:<\/p>\n<ul>\n<li><a href=\"https:\/\/support.apple.com\/en-us\/HT201675\">File Quarantine<\/a> requires explicit user confirmation before a file downloaded from the Internet can execute.<\/li>\n<li><a href=\"https:\/\/support.apple.com\/guide\/security\/gatekeeper-and-runtime-protection-sec5599b66df\/web%22\">Gatekeeper<\/a> blocks the installation of apps unless they\u2019re signed by a developer known to Apple.<\/li>\n<li>Mandatory <a href=\"https:\/\/support.apple.com\/guide\/security\/protecting-against-malware-sec469d47bd8\/web\">App Notarization<\/a> permits apps to be installed only after Apple has scanned them for malware.<\/li>\n<\/ul>\n<p>Earlier this year, a piece of malware well known to Mac security experts began exploiting a vulnerability that allowed it to completely suppress all three mechanisms. Called Shlayer, it has an impressive record in the three years since it appeared.<\/p>\n<p>Last September, for instance, it managed to <a href=\"https:\/\/arstechnica.com\/information-technology\/2020\/09\/mac-malware-gets-apples-seal-of-approval-thanks-to-notarization-goof\/\">pass the security scan<\/a> that Apple requires for apps to be notarized. Two years ago, it was delivered in a sophisticated campaign that <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/01\/malvertisers-target-mac-uses-with-stenographic-code-stashed-in-images\/\">used novel steganography<\/a> to evade malware detection. And last year, Kaspersky said Shlayer was the <a href=\"https:\/\/arstechnica.com\/information-technology\/2020\/01\/mac-users-are-getting-bombarded-by-laughably-unsophisticated-malware\/\">most detected Mac malware<\/a> by the company\u2019s products, with almost 32,000 different variants identified.<\/p>\n<h2>Clever evasion<\/h2>\n<p>Shlayer\u2019s exploitation of the zero-day, which started no later than January, represented yet another impressive feat. Rather than using the standard <a href=\"https:\/\/en.wikipedia.org\/wiki\/Mach-O\">Mach-O<\/a> format for a Mac executable, the executable component in this attack was the macOS script, which executes a series of line commands in a particular order.<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>Normally, scripts downloaded from the Internet are classified as application bundles and are subject to the same requirements as other types of executables. A simple hack, however, allowed scripts to completely shirk those requirements.<\/p>\n<p>By removing the <a href=\"https:\/\/developer.apple.com\/library\/archive\/documentation\/General\/Reference\/InfoPlistKeyReference\/Articles\/AboutInformationPropertyListFiles.html\">info.plist<\/a>\u2014a structured text file that maps the location of files it depends on\u2014the script no longer registered as an executable bundle to macOS. Instead, the file was treated as a PDF or other type of non-executable file that wasn\u2019t subject to Gatekeeper and the other mechanisms.<\/p>\n<p>One of the attacks began with the display of an ad for a fake Adobe Flash update:<\/p>\n<figure class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/04\/fake-flash-update.jpeg\" class=\"enlarge\" data-height=\"1018\" data-width=\"1600\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/04\/fake-flash-update-640x407.jpeg\" width=\"640\" height=\"407\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/04\/fake-flash-update-1280x814.jpeg 2x\"><\/a><figcaption class=\"caption\"><\/figcaption><\/figure>\n<p>The videos below show what a big difference the exploit made once someone took the bait and clicked download. The video immediately below depicts what the viewer saw with the restrictions removed. The one below that shows how much more suspicious the update would have looked had the restrictions been in place.<\/p>\n<figure class=\"video\">\n<div class=\"wrapper\"><iframe loading=\"lazy\" type=\"text\/html\" width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/MtCk0JHzUYo?start=0&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen>[embedded content]<\/iframe><\/div><figcaption class=\"caption\">\n<div class=\"caption-text\">Shlayer attack with exploit of CVE-2021-30657.<\/div>\n<\/figcaption><\/figure>\n<figure class=\"video\">\n<div class=\"wrapper\"><iframe loading=\"lazy\" type=\"text\/html\" width=\"560\" height=\"315\" src=\"https:\/\/www.youtube.com\/embed\/GPMENlgHRhk?start=0&amp;wmode=transparent\" frameborder=\"0\" allowfullscreen>[embedded content]<\/iframe><\/div><figcaption class=\"caption\">\n<div class=\"caption-text\">Shlayer attack without exploit of CVE-2021-30657.<\/div>\n<\/figcaption><\/figure>\n<p>The bug, which is tracked as CVE-2021-30657, was discovered and reported to Apple by security researcher Cedric Owens. He said he stumbled upon it as he was using a developer tool called Appify while performing research for a \u201cred team\u201d exercise, in which hackers simulate a real attack in an attempt to find previously overlooked security weaknesses.<\/p>\n<p>\u201cI found that Appify was able to turn a shell script into a double clickable \u2018app\u2019 (really just a shell script inside of the macOS app directory structure but macOS treated it as an app),\u201d he wrote in a direct message. \u201cAnd when executed it bypasses Gatekeeper. I actually reported it pretty quickly after discovering it and did not use it in a live red team exercise.\u201d<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>Apple <a href=\"https:\/\/support.apple.com\/en-us\/HT212325\">fixed the vulnerability<\/a> with Monday\u2019s release of macOS 11.3. Owens said that the flaw appears to have existed since the introduction of macOS 10.15 in June 2019, which is when notarization was introduced.<\/p>\n<p>Owens discussed the bug with Patrick Wardle, a Mac security expert who previously worked at Jamf, a Mac enterprise security provider. Wardle then reached out to Jamf researchers, who uncovered the Shlayer variant that was exploiting the vulnerability before it was known to Apple or most of the security world.<\/p>\n<p>\u201cOne of our detections alerted us to this new variant, and upon closer inspection we discovered its use of this bypass to allow it to be installed without an end user prompt,\u201d Jamf researcher Jaron Bradley told me. \u201cFurther analysis leads us to believe that the developers of the malware discovered the zeroday and adjusted their malware to use it, in early 2021.\u201d<\/p>\n<p>Wardle developed a proof-of-concept exploit that showed how the Shlayer variant worked. After being downloaded from the Internet, the executable script appears as a PDF file named Patrick\u2019s Resume. Once someone doubleclicks on the file, it launches a file called calculator.app. The exploit could just as easily execute a malicious file.<\/p>\n<figure class=\"image shortcode-img center full\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/04\/PoC.gif\" width=\"600\" height=\"546\"><figcaption class=\"caption\">\n<div class=\"caption-credit\">Patrick Wardle<\/div>\n<\/figcaption><\/figure>\n<p>In a <a href=\"https:\/\/objective-see.com\/blog\/blog_0x64.html\">12,000-word deep-dive<\/a> that delves into the causes and effects of the exploits, Wardle concluded:<\/p>\n<blockquote>\n<p>Though this bug is now patched, it clearly (yet again) illustrates that macOS is not impervious to incredible shallow, yet hugely impactful flaws. How shallow? Well that fact that a legitimate developer tool (appify) would inadvertently trigger the bug is beyond laughable (and sad).<\/p>\n<p>And how impactful? Basically macOS security (in the context of evaluating user launched applications, which recall, accounts for the vast majority of macOS infections) was made wholly moot.<\/p>\n<\/blockquote>\n<p>Bradley published a <a href=\"https:\/\/www.jamf.com\/blog\/shlayer-malware-abusing-gatekeeper-bypass-on-macos\/\">post<\/a> that recounted how the exploit looked and worked.<\/p>\n<p>Many people consider malware like Shlayer unsophisticated because it relies on tricking its victims. To give Shlayer its due, the malware is highly effective, in large part because of its ability to suppress macOS defenses designed to tip-off users before they accidentally infect themselves. Those who want to know if they&#8217;ve been targeted by this exploit can download <a href=\"https:\/\/objective-see.com\/downloads\/blog\/blog_0x64\/scan.py\">this<\/a> python script written by Wardle.<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32237\/Actively-Exploited-Mac-0-Day-Neutered-Core-OS-Defenses.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":40622,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[9154],"class_list":["post-40621","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlineflawpatchapple"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-27T15:17:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"534\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Actively Exploited Mac 0-Day Neutered Core OS Defenses\",\"datePublished\":\"2021-04-27T15:17:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/\"},\"wordCount\":1033,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg\",\"keywords\":[\"headline,flaw,patch,apple\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/\",\"name\":\"Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg\",\"datePublished\":\"2021-04-27T15:17:22+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg\",\"width\":800,\"height\":534},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/actively-exploited-mac-0-day-neutered-core-os-defenses\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,flaw,patch,apple\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlineflawpatchapple\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Actively Exploited Mac 0-Day Neutered Core OS Defenses\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/","og_locale":"en_US","og_type":"article","og_title":"Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-04-27T15:17:22+00:00","og_image":[{"width":800,"height":534,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Actively Exploited Mac 0-Day Neutered Core OS Defenses","datePublished":"2021-04-27T15:17:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/"},"wordCount":1033,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg","keywords":["headline,flaw,patch,apple"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/","url":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/","name":"Actively Exploited Mac 0-Day Neutered Core OS Defenses 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg","datePublished":"2021-04-27T15:17:22+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/04\/actively-exploited-mac-0-day-neutered-core-os-defenses.jpg","width":800,"height":534},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/actively-exploited-mac-0-day-neutered-core-os-defenses\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,flaw,patch,apple","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlineflawpatchapple\/"},{"@type":"ListItem","position":3,"name":"Actively Exploited Mac 0-Day Neutered Core OS Defenses"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40621","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=40621"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/40621\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/40622"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=40621"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=40621"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=40621"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}