Description
This module exploits CVE-2024-27822, a vulnerability in macOS PackageKit.framework where PKG installer scripts using a ZSH shebang (#!/bin/zsh) are executed as root while inheriting the installing user's environment. This causes ZSH to load the user's ~/.zshenv with root privileges before the installer script body runs.
The module injects a payload into ~/.zshenv that only fires when EUID is 0, uploads a minimal PKG (from data/exploits/CVE-2024-27822/template.pkg) whose install script uses a #!/bin/zsh shebang, and opens it with Installer.app. When the user approves the installation dialog and authenticates, PackageKit runs the install script as root. ZSH sources ~/.zshenv before the script body executes, so the payload fires with root privileges. The original ~/.zshenv content is restored immediately after the payload runs.
Affected: macOS 14.4 and earlier, 13.6.6 and earlier, 12.7.4 and earlier, and all macOS 11 and older releases. Fixed in: macOS 14.5, 13.6.7, 12.7.5.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/osx/local/packagekit/zshenv_privescmsf undefined(zshenv_privesc) > show actions ...actions...msf undefined(zshenv_privesc) > set ACTION < action-name >msf undefined(zshenv_privesc) > show options ...show and set options...msf undefined(zshenv_privesc) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub