It is trivial to escalate to root and then do precisely that when SIP is disabled.
That's because more recently Apple introduced an entitlement to make that trivial, right? I wish they hadn't done that.
Yes but it's natural considering that their security model is built on SIP being enabled
That's because more recently Apple introduced an entitlement to make that trivial, right? I wish they hadn't done that.
Yes but it's natural considering that their security model is built on SIP being enabled