CVE-2019-8656

MEDIUM

macOS < 10.14.6 - Gatekeeper Bypass via Symbolic Link in NFS Mount

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-8656. PoCs published by D00MFist.

AI-analyzed exploit summary This PoC exploits CVE-2019-8656, a Gatekeeper bypass vulnerability in macOS, by creating a malicious .app bundle with a symlink to an NFS share, allowing arbitrary code execution when the user opens the application. The exploit involves setting up an NFS server and crafting a zip file with a symlink to bypass Gatekeeper's quarantine checks.

Description

This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.

Exploits (1)

nomisec WORKING POC 2 stars
by D00MFist · poc
https://github.com/D00MFist/CVE-2019-8656

This PoC exploits CVE-2019-8656, a Gatekeeper bypass vulnerability in macOS, by creating a malicious .app bundle with a symlink to an NFS share, allowing arbitrary code execution when the user opens the application. The exploit involves setting up an NFS server and crafting a zip file with a symlink to bypass Gatekeeper's quarantine checks.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: macOS Gatekeeper (versions affected by CVE-2019-8656)
No auth needed
Prerequisites: Access to a macOS target · Ability to host an NFS share · User interaction to open the malicious .app bundle
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT210348

Scores

CVSS v3 5.5
EPSS 0.0377
EPSS Percentile 88.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (1)
apple/mac_os_x < 10.14.6
Published Oct 27, 2020
Tracked Since Feb 18, 2026