# 0day Bypasses Apple SIP via Upgrade Process

Published: 2026-08-02 · Severity: medium
Canonical: https://vorant.io/reports/cce5c828-33a0-5bc3-a8d8-fd18721c150a/0day-bypasses-apple-sip-via-upgrade-process

> Researcher demonstrates an unpatched macOS 0day that abuses the local OS upgrade/bless process to bypass System Integrity Protection and implant undeletable malware.

Patrick Wardle of Objective-See disclosed an unpatched 0day allowing attackers with existing local access to a macOS system to bypass System Integrity Protection (SIP), the OS-level sandbox introduced in El Capitan that restricts even root-level code from modifying protected system files. The technique abuses the local OS upgrade/installer workflow: the installer's helper process (osishelperd) carries the undocumented com.apple.rootless.install.heritable entitlement, which lets it and its children (including the bless utility) bypass SIP restrictions to set the startup disk to an installer disk image. Because the embedded InstallESD.dmg/BaseSystem.dmg upgrade images are not signature-verified before being blessed and booted, an attacker who has already compromised a Mac can hijack a local dylib within the installer app (via dylib proxying, since binary patching would break code signing) to hook the extractBootBits method and inject malicious code into BaseSystem.dmg before it is used to boot the second install phase.

## Mentioned in this report

- Malware: iWorm

Source reporting: https://objective-see.org/blog/blog_0x14.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cce5c828-33a0-5bc3-a8d8-fd18721c150a/0day-bypasses-apple-sip-via-upgrade-process.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
