Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix
Zhongquan Li
OffensiveCon 2026 · Day 2 · Main Stage
In his OffensiveCon 2026 presentation, "Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix," independent security researcher Zhongquan Li delved into a series of persistent and high-impact vulnerabilities rooted in fundamental design flaws within macOS security mechanisms. Li's research, conducted between 2024 and 2025, highlights how Apple's layered security often introduces unintended bypasses or leaves core issues unaddressed, leading to attack surfaces that can remain exploitable for extended periods, sometimes years. The talk showcased several powerful techniques, including remote one-click **TCC (Transparency, Consent, and Control)** bypasses, novel persistence methods leveraging **Data Vault** protections, and circumventions of macOS's **non-atomic operation security**.
AI review
Li is doing real original macOS security research — multiple novel attack chains, live demos, and a coherent thesis that design-based flaws are structurally harder for Apple to kill than memory corruption bugs. The inode brute-force trick alone is worth the ticket, and the persistent SUID-in-Data-Vault angle is the kind of thing that makes EDR vendors quietly update their slides.