macOS 'Migraine' Exploit Capable of Bypassing System Integrity Protection Detected by Microsoft

Microsoft identified the exploit in a macOS tool used to migrate data from a Windows PC to a Mac, or from one Mac to another.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 31 May 2023 17:59 IST
Highlights
  • Microsoft detected a flaw that could allow modification of system files
  • System Integrity Protection was first introduced on macOS in 2015
  • Apple has patched the security vulnerability with macOS 13.4

Users who have updated to macOS 13.4 should be protected against the Migraine exploit

Photo Credit: Apple

Microsoft recently detected a security exploit that could allow attackers to bypass a core security feature on computers running on macOS. Dubbed "Migraine", the vulnerability can be used to sidestep Apple's System Integrity Protection (SIP) on macOS — a feature that protects parts of the operating system related to system integrity by restricting access to certain files — and install malware on a victim's computer. Microsoft warned Apple about the security flaw and the Cupertino company has patched the flaw with its latest security update.

According to details shared by Microsoft in a blog post, the "Migraine" security exploit relies on Migration Assistant, a tool provided by Apple to allow users to transfer files from one Mac to another or from a Windows PC to a Mac. The Migration Assistant app from Apple has unrestricted root access that allows it to perform its data transfer function, and security researchers at Microsoft leveraged the special 'entitlement' given to the tool, for the exploit.

Advertisement

After modifying the Migration Assistant to run without logging off a user, Microsoft was able to run the tool in debug mode to bypass a signature check. The company used a 1GB Time Machine backup with malicious software, using a script to cause Migration Assistant to import the backup and infect the host system. The entire process bypassed the System Integrity Protection feature that was first introduced on macOS in 2015.

Microsoft's modified Migration Assistant can function without signing out
Photo Credit: Microsoft

Advertisement

 

It is worth noting that the Migration Assistant is typically available during user setup, which means that an attacker would need to have local access to a machine. Microsoft says that the arbitrary system bypasses like Migraine could create files that are protected by SIP, the same mechanism that it bypasses, making deletion very difficult. Attackers can also run arbitrary kernel code and tamper with the system to enable rootkits. Microsoft adds that these exploits can also be used to gain access to private data as well as computer accessories and devices.

Advertisement

Users who have updated their computers to macOS 13.4 after it was rolled out on May 18 should be safe from the exploit, which has been patched by Apple. Microsoft disclosed the security flaw to Apple, allowing the firm to roll out a fix for the issue. Meanwhile, the company has thanked Microsoft's Jonathan Bar Or, Anurag Bohra, and Michael Pearse for identifying the exploit.


Google I/O 2023 saw the search giant repeatedly tell us that it cares about AI, alongside the launch of its first foldable phone and Pixel-branded tablet. This year, the company is going to supercharge its apps, services, and Android operating system with AI technology. We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  3. These Three Pro Models Could Launch as Part of the Motorola Edge 70 Series
  4. Realme 16 5G Launched in India With Selfie Mirror Feature: Check Price
  5. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  6. Google Pixel 11 Pro XL CAD Renders Leak Online
  7. Meta Reportedly Warns WhatsApp Users About This Fake App Spying on Them
  8. Best Mobiles Under Rs. 30,000 in India
  9. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  10. Redmi Note 15 SE 5G Debuts in India With a Vegan Leather Finish: See Price
  1. OpenAI Brings ChatGPT to Apple CarPlay, but It Cannot Access Navigation and Live Location Data
  2. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale; iPad, Watch Available With Offers
  3. Google Pixel 11 Pro XL Leaked CAD Renders Reveal Design Identical to Pixel 10 Pro XL
  4. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  5. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  6. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  7. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  8. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  9. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  10. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.