🔐 Security bulletin — After “Dylib Hijacking: Dead or Alive?”
Verdict: alive (with fewer hiding spots).
Patrick Wardle
@patrickwardle walked us from the OG research to macOS 26, then proved on stage that sloppy search paths, loose rpath habits, and mis-bundled PlugIns still open the door.
Do now: audit rpath/loader_path/executable_path, lock bundles with Hardened Runtime Library Validation, and alert on unexpected Frameworks/PlugIns loading inside app bundles.
Classic technique, modern teeth. Only at
#OBTS 🍏 do you get the history, the live receipts, and the fix—back-to-back.