Privilege Separation
macOS enforces a robust privilege separation model to limit the impact of compromised processes. This model relies on user accounts, entitlements, and process isolation to ensure that even if an attacker gains access to a single component, they cannot escalate privileges or access sensitive system resources. Understanding these mechanisms is critical for both defensive analysis and offensive testing scenarios.
User Accounts and Privilege Levels¶
macOS uses user accounts to enforce least-privilege access. By default, all users operate with standard permissions, while administrative tasks require elevation via sudo. The system also employs a dedicated root account, which is typically disabled by default and should only be used in specific maintenance scenarios.
Key concepts:
- Standard users: Cannot modify system files or install software without sudo.
- Admin users: Can grant themselves sudo privileges to perform elevated tasks.
- Root account: Disabled by default; enabling it bypasses standard privilege checks, making it a high-risk configuration.
Example:
Entitlements and Code Signing¶
Entitlements are permissions explicitly requested by an application to perform specific actions (e.g., accessing the network, reading files). These are defined in the app’s entitlements file and must be signed with a trusted certificate. macOS enforces entitlements through code signing, ensuring only authorized apps can execute privileged operations.
Key concepts:
- Code signing: Apps must be signed to request entitlements.
- Entitlements file: Contains permissions like com.apple.security.temporary-exception.apple-events or com.apple.private.apsd.
- System integrity checks: Apps without valid entitlements are blocked from performing privileged tasks.
Example:
Process Isolation and Sandboxing¶
macOS isolates processes using sandboxing, which restricts access to system resources. Sandboxed apps can only interact with specific APIs and files, unless explicitly granted permissions via entitlements. This prevents malicious code from spreading across the system.
Key concepts:
- App Sandboxing: Enforced by the kernel and sandboxd daemon.
- Launchd isolation: System services run with limited privileges, even if compromised.
- Sandboxed processes: Cannot access arbitrary files or network resources without entitlements.
Example:
System Integrity Protection (SIP)¶
SIP, introduced in macOS 10.11, prevents unauthorized modifications to system files and processes. It restricts access to critical directories like /System, /sbin, and /usr, even for root users. SIP is a core component of macOS’s privilege separation model.
Key concepts:
- SIP status: Enabled by default; can be toggled via csrutil.
- Protected directories: Cannot be modified without disabling SIP.
- Kernel extensions: Require SIP to be disabled for installation.
Example:
Key takeaways¶
- User accounts enforce least-privilege access, with
sudomanaging elevation. - Entitlements and code signing control app permissions, preventing unauthorized actions.
- Sandboxing isolates processes, limiting their ability to access system resources.
- SIP protects critical system components from tampering, even by root users.
- Understanding these layers is essential for both defending against privilege escalation and testing system resilience.