Chekhov's Gun: Uncovering Hidden Risks in macOS Application-Sandboxed PID-Domain Services
Minghao Lin, Jiaxun Zhu, Tingting Yin, Zechao Cai, Guanxing Wen, Yanan Guo, Mengyuan Li
2025Year
Abstract
macOS delegates many high-privilege operations to dedicated PID-domain services, which applications can register and communicate with through inter-process communication (IPC). This architecture improves userland stability and security but also introduces attractive attack surfaces for adversaries. In this paper, we systematically analyze PID-domain services and uncover an overlooked attack vector: PID-domain services that are restricted to an Application Sandbox identical to the calling application can still be exploited due to subtle entitlement differences.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOSLuke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu et al.S&P 2020 · 10 citations
- Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the ComputerThanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan et al.USENIX Security 2018 · 25 citations
- File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification System on Linux, Windows, and macOSSudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner et al.CCS 2026
- Peep With A Mirror: Breaking The Integrity of Android App Sandboxing via Unprivileged Cache Side ChannelYan Lin, Joshua Wong, Xiang Li, Haoyu Ma et al.USENIX Security 2024 · 2 citations
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian et al.CCS 2016 · 41 citations
