
Exploit for CVE-2023-42860
Exploit for CVE-2023-42860 (for research purposes only).
This exploit works for versions of macOS earlier to 13.3, even though Apple´s changelog says it was fixed in version 14.1.
TARGET_FILE on the exploit.sh file to a SIP protected file on the system (default target is the system TCC database).$ ./exploit.sh PATH_TO_PKG
/Applications/Install\ macOS\ Ventura.app/Contents/SharedSupport/SharedSupport.dmg. The file has to be modified as the root user.https://blog.kandji.io/apple-mitigates-vulnerabilities-installer-scripts