Standard Mac Users Can Silence Endpoint Defenses

A low-privilege macOS foothold can now mute the tools meant to watch it. The gap is in trust handling: once macOS has cached an app’s identity, a standard user can make a privileged helper accept a request as if it came from trusted vendor code, then carry out admin-only actions without admin rights or a kernel exploit. XM Cyber showed the issue by disabling CrowdStrike Falcon and Kandji on macOS through this path, and said the same pattern can apply to other apps that expose privileged XPC services. The affected boundary is the one many security and MDM agents rely on to install components, reach telemetry, or unload protections. The practical risk is telemetry loss after user compromise. On fleets that depend on privileged XPC helpers, a normal account takeover can become a blind spot instead of staying contained inside the endpoint.

Part of the PlainSec briefing for 2026-06-26

Sources