# tcc (blogs) — RSS Amplifier

Recent posts from the 5 feeds in the RSS Amplifier directory that cover tcc.

Page: <https://rssamplifier.com/topics/tcc/blogs>  
Feed: <https://rssamplifier.com/topics/tcc/blogs.md>

---

## [Road trip Skotlannin Ylämailla](https://netammelat.fi/eurooppa/skotlanti/road-trip-skotlannin-ylamailla/?pk_campaign=feed&#038;pk_kwd=road-trip-skotlannin-ylamailla)

_2026-08-15 · Ne Tammelat · Ne Tammelat_

Kun yhdistetään yksi vuoden kovimmista talvimyrskyistä Skotlannissa ja road trip Ylämaille, on yhdistelmänä takuuvarmasti seikkailuntäyteinen päivä.

## [Escaping the Apple Sandbox by Spawning an Executable](https://wts.dev/posts/sandbox-spawnattrs-escape/)

_2026-07-30 · Watch This Space_

## [Glasgow &#8211; Skotlannin piilotettu helmi](https://netammelat.fi/eurooppa/skotlanti/glasgow-piilotettu-helmi/?pk_campaign=feed&#038;pk_kwd=glasgow-piilotettu-helmi)

_2026-07-19 · Ne Tammelat · Ne Tammelat_

Glasgow'sta löytyy niin rosoista kaupunkikuvaa kuin upeita historiallisia rakennuksia, viihtyisiä viheralueita ja tunnelmallisia pubeja.

## [Crossing the Golden Gate: macOS's New Application Support Protection](/post/golden-gate-appdata-protection/)

_2026-07-16 · Wojciech Reguła_

Summary Looks like moving the user&rsquo;s TCC db to /private/var/containers/Data/ProtectedSystem/\[UUID\]/Data/Library/Application Support/com.apple.TCC/ was not the only change in the whole privacy castle macOS 27. (What btw was a great move as now attackers with full disk access permissions can&rsquo;t modify your privacy settings) macOS 27 quietly ships a new privacy mechanism I hadn&rsquo;t…

## [NomadManian matka Moldovaan ja Transnistriaan](https://netammelat.fi/eurooppa/moldova/nomadmania-moldova-ja-transnistria/?pk_campaign=feed&#038;pk_kwd=nomadmania-moldova-ja-transnistria)

_2026-06-19 · Ne Tammelat · Ne Tammelat_

Millainen maa on EU:hun pyrkivä Moldova ja miltä elämä näyttää lähes täysin muusta maailmasta eristyksissä olevassa Transnistriassa?

## [Kroatian saaristossa purjehtimassa](https://netammelat.fi/eurooppa/kroatia/kroatian-saaristo-purjehdus/?pk_campaign=feed&#038;pk_kwd=kroatian-saaristo-purjehdus)

_2026-05-31 · Ne Tammelat · Ne Tammelat_

Purjehdus Kroatian saaristossa oli upea kokemus: Adrianmeren turkoosit poukamat ja lähisaarien tunnelmalliset pikkukylät hurmasivat meidät.

## [Design-Based Vulnerabilities on macOS： Oops, Not a One-Shot Fix](/apple/macos/2026/05/15/Design-Based-Vulnerabilities-on-macOS-Oops-Not-a-One-Shot-Fix.html)

_2026-05-15 · Zhongquan Li’s blogs_

Preface 0. macOS Userland : Based on Old Apple Bug Bounty 0.1 Userland Root LPE 0.2 General / Full TCC Bypass 0.3 SIP : System Integrity Protection 1. Remote Full TCC Bypass And Persistence 1.1 Threat model 1.2 package\_script\_service 1.3 Data Vault 1.4 Persistence 1.5 Easter Eggs in My Black Hat USA 2024 Presentation 1.6 How Apple Verifies / Protects the Integrity of An App 1.7 Exploit Steps 1.7.1…

## [Arabiemiirikunnat &#8211; 6 emiraattia ja pyöräilyä aavikolla](https://netammelat.fi/lahi-ita/arabiemiirikunnat/6-emiraattia-pyoraily-aavikolla/?pk_campaign=feed&#038;pk_kwd=6-emiraattia-pyoraily-aavikolla)

_2026-05-03 · Ne Tammelat · Ne Tammelat_

Yhdistyneet Arabiemiirikunnat koostuvat seitsemästä emiraatista, joista kuudessa kävimme. Myös pyöräretki aavikkoradalla oli hieno kokemus.

## [Päiväretki Saudi-Arabiaan](https://netammelat.fi/aasia/saudi-arabia/paivaretki-saudi-arabiaan/?pk_campaign=feed&#038;pk_kwd=paivaretki-saudi-arabiaan)

_2026-04-06 · Ne Tammelat · Ne Tammelat_

Teimme oppaan johdolla Bahrainista päiväretken Saudi-Arabiaan. Kohteemme olivat Heritage Village Dammam sekä Ithran moderni kulttuurikeskus.

## [Bahrain &#8211; Persianlahden pieni saarivaltio](https://netammelat.fi/lahi-ita/bahrain/bahrain-persianlahti-saarivaltio/?pk_campaign=feed&#038;pk_kwd=bahrain-persianlahti-saarivaltio)

_2026-03-29 · Ne Tammelat · Ne Tammelat_

Bahrain on Persianlahden pienin valtio. Se on kehittynyt viime vuosina nopeasti varteenotettavaksi matkakohteeksi naapurimaidensa rinnalle.

## [profullstack on Ko‑fi (Sponsored)](https://crawlproof.com/a/DfZzI0tbXvZW)

_2026-03-29 · **Sponsored**_

Open the creator's Ko‑fi page.

## [Talvinen Lappeenranta ja Imatra](https://netammelat.fi/eurooppa/suomi/talvinen-lappeenranta-ja-imatra/?pk_campaign=feed&#038;pk_kwd=talvinen-lappeenranta-ja-imatra)

_2026-03-22 · Ne Tammelat · Ne Tammelat_

Ota viikonloppukohteeksi Lappeenranta ja Imatra talvikaudella. Molemmista kaupungeista löytyy persoonallisia majoituksia ja herkullista ruokaa.

## [How I "hacked" ChatGPT Atlas... and why it wasn't patched](https://wts.dev/posts/chatgpt-atlas-bug/)

_2026-02-16 · Watch This Space_

## [Outlander-kiertomatka Skotlannissa](https://netammelat.fi/eurooppa/skotlanti/outlander-kiertomatka-skotlannissa/?pk_campaign=feed&#038;pk_kwd=outlander-kiertomatka-skotlannissa)

_2026-02-08 · Ne Tammelat · Ne Tammelat_

Suosittua Outlander-sarjaa on kuvattu Skotlannin useissa eri kaupungeissa ja se esittelee maan maisemia sekä historiallisia kohteita upeasti.

## [CVE-2025-43530: Exploiting a private API for VoiceOver](https://jhftss.github.io/CVE-2025-43530/)

_2025-12-31 · Mickey’s Blogs_

Happy New Year in advance!

## [DirtyDict: Escaping the macOS Sandbox and wrecking havoc](https://wts.dev/posts/dirtydict/)

_2025-12-18 · Watch This Space_

## [I Know The Name Of Your Wi-Fi Network](https://wts.dev/posts/ipconfig/)

_2025-10-22 · Watch This Space_

## [I wrote an Objective-C bridge for Node.js. Don't use it.](https://wts.dev/posts/nobjc/)

_2025-10-03 · Watch This Space_

## [Exploiting the Impossible: A Deep Dive into A Vulnerability Apple Deems Unexploitable](https://jhftss.github.io/Exploiting-the-Impossible/)

_2025-09-04 · Mickey’s Blogs_

This is a blog post for my presentation at the conference Nullcon Berlin 2025. The slides are uploaded here.

## [CVE-2025-24103 : General TCC Bypass](/apple/macos/tcc/2025/08/07/CVE-2025-24103-General-TCC-Bypass.html)

_2025-08-07 · Zhongquan Li’s blogs_

0. CVE-2025-24103 : GuluBadInstallAssistant 1. Detail 1.1 What if we could execute the osinstallersetupd command successfully? 1.2 src 1.3 dst 2. Exploit Step 1: Prepare the malicious file on your own macOS Step 2: Download the malicious file malicious-osinstallersetupd.zip to the victim macOS 3. 14 G ? No, it’s 24M or less 4. Demo 5. Patch : macOS 15.3 6. One more thing 0. CVE-2025-24103 :…

## [CVE-2025-43253: Bypassing Launch Constraints on macOS](https://wts.dev/posts/bypassing-launch-constraints/)

_2025-07-31 · Watch This Space_

## [Never miss a game (Sponsored)](https://crawlproof.com/a/pNPxGn9l0xWQ)

_2025-07-31 · **Sponsored**_

Follow any team; get an hour and one-minute web and email reminders.

## [Can You Really Trust That Permission Pop-Up On macOS? (CVE-2025-31250)](https://wts.dev/posts/tcc-who/)

_2025-05-12 · Watch This Space_

## [CVE-2025-24259: Leaking Bookmarks on macOS](https://wts.dev/posts/bookmarks-leak/)

_2025-03-31 · Watch This Space_

## [Leaking Passwords (and more!) on macOS](https://wts.dev/posts/password-leak/)

_2025-03-20 · Watch This Space_

## [Dropping a 0 day: Parallels Desktop Repack Root Privilege Escalation](https://jhftss.github.io/Parallels-0-day/)

_2025-02-20 · Mickey’s Blogs_

Today, I am disclosing a 0-day vulnerability that bypasses the patch for CVE-2024-34331. I have identified two distinct methods to circumvent the fix. Both bypasses were reported separately to the Zero Day Initiative (ZDI) and the affected vendor Parallels. Unfortunately, their responses have been deeply unsatisfactory.

## [Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times](https://jhftss.github.io/Endless-Exploits/)

_2025-01-31 · Mickey’s Blogs_

This is a blog post for my presentation at the conference OBTS v7.0. The slides are uploaded here.

## [CVE-2024-54527: MediaLibraryService Full TCC Bypass, Dive Deep into AMFI](https://jhftss.github.io/CVE-2024-54527-MediaLibraryService-Full-TCC-Bypass/)

_2025-01-08 · Mickey’s Blogs_

Happy New Year!

## [CVE-2024-54471: A Primer](https://wts.dev/posts/CVE-2024-54471-primer/)

_2024-12-12 · Watch This Space_

## [Some Experience In Apple Security Bug Program](/experience/2024/11/28/Some-Experience-In-ASB.html)

_2024-11-28 · Zhongquan Li’s blogs_

Do the research on macOS for around 1 year, share some of my experience in Apple Security Bug Program.

## [A New Era of macOS Sandbox Escapes: Diving into an Overlooked Attack Surface and Uncovering 10+ New Vulnerabilities](https://jhftss.github.io/A-New-Era-of-macOS-Sandbox-Escapes/)

_2024-11-07 · Mickey’s Blogs_

This is a blog post for my presentation at the conference POC2024. The slides are uploaded here.

## [TCC bypasses via launch services](/post/tcc-bypasses-via-launch-services/)

_2024-10-20 · Wojciech Reguła_

Overview of my favorite TCC bypass ever This vulnerability was disclosed at Black Hat Europe 2022 in the talk Knockout Win Against TCC - 20+ NEW Ways to Bypass Your MacOS Privacy Mechanisms. The technique used an old Launch Services function LSSetDefaultRoleHandlerForContentType that allowed (without any restrictions) to register arbitrary applications for handling specified UTI handlers. After…

## [CLI-first decentralized compute (Sponsored)](https://crawlproof.com/a/W0qzHI9IgwH4)

_2024-10-20 · **Sponsored**_

Run and pay spare GPUs from the CLI — transcode, coinpay (DID+escrow), infernet (AI).

## [SQL Injection in TCC: and why it (probably) wasn't a security risk (this time)](https://wts.dev/posts/tcc-sql-injection/)

_2024-09-16 · Watch This Space_

## [Unveiling Mac Security: A Comprehensive Exploration of Sandboxing and AppData TCC](/apple/macos/2024/08/24/Unveiling-Mac-Security-A-Comprehensive-Exploration-of-TCC-Sandboxing-and-App-Data-TCC.html)

_2024-08-24 · Zhongquan Li’s blogs_

Preface 1. Security Protections on macOS 1.1 System Integrity Protection: Rootless 1.2 Transparency, Consent, and Control : TCC 2. Transforming a Traditionally Useless Bug into a Sandbox Escape: A General Application Sandbox Escape Approach 2.1 Remote Attack Surfaces on macOS 2.2 App Sandbox Escape on macOS 2.3 Quarantine Protection on macOS 2.3.1 Quarantine Protection on macOS: Untrusted App…

