Sitemap

Breaking Hardened Runtime

The 0-Day Microsoft Delivered to macOS

Sep 15, 2025

--

Press enter or click to view image in full size

Microsoft’s .NET MAUI framework for macOS has a vulnerability that bypasses the Hardened Runtime protection by not enforcing code signing validation on managed DLLs in the MonoBundle directory.

It permits arbitrary code injection through modified assemblies even though the main executable is properly signed and hardened.

As a result, all .NET MAUI macOS applications are vulnerable to code injection, privilege escalation, and TCC permission bypasses.

You can find the article on the AFINE blog where I published it: https://afine.com/breaking-hardened-runtime-the-0-day-microsoft-delivered-to-macos/

--

--

No responses yet