
The Cat Chronicles: Breaking Sandboxes and Snatching Cookies | SO-CON 2025
Source: YouTube · SpecterOps · published May 7, 2025 · 44:14
The presenter shares advanced Mac OS red team techniques, including TCC bypasses and browser cookie extraction, to educate the community on macOS security mechanisms.
Key Takeaways:
• The speaker has over 10 years of red team experience across AD, GCP, and Linux, now focusing on Mac OS to address the lack of visible macOS security research 0:32.
• The presentation covers new Mac OS techniques, specifically detailing TCC (Transparency, Consent, and Control) bypasses and methods for breaking sandboxes 0:12.
• A key demonstration involves extracting browser cookies without any user interaction, highlighting significant privacy and security risks 0:18.
• The goal is to provide a comprehensive understanding of how macOS works internally to improve defensive strategies and awareness 0:50.
By exposing these advanced exploitation vectors, the talk aims to bridge the knowledge gap in macOS security and encourage better protective measures.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Music] We have a lot to cover here actually. So, we're going to have to talk about Mac OS techniques, new techniques, and um as the name says here, we're going to talk about uh the cat chronicles, uh TCC bypasses, breaking sandboxes, getting cookies from the browser without user interaction. So, there's a lot of stuff to cover here today. So just presenting myself who am I actually? So I have 10 years plus of red team experience. Um I test a lot of environments AD on prem as uh as GCP Linux. Currently I'm testing a lot of Mac OS. So I hear a lot of people just saying well we don't see Mac OS a lot. So I hope that this presentation can actually give you give you guys um a good idea about how Mac OS actually works. So um I also have some community contributions. So um I developed darkmail c…