Get the latest tech news

Root Persistence via macOS Recovery Mode Safari


I accidentally discovered 2 vulnerabilities in macOS Recovery Mode's Safari: one allowing arbitrary writes to system partitions and root persistence (CVSS 8.5), the other allowing unrestricted file reads (CVSS 4.6).

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Safari

Safari

Photo of macos recovery mode

macos recovery mode

Photo of root persistence

root persistence

Related news:

News photo

Safari's Compact Tab Bar Is Back on Mac and iPad

News photo

WebKit Features for Safari 26.4

News photo

macOS Tahoe 26.4 Now Available With Safari Compact Tab Bar, Battery Charge Limits and More