Skip to content

TCC Database Manipulation

macOS's Transparency, Consent, and Control (TCC) framework enforces access restrictions for applications to sensitive system resources. By manipulating the TCC database, red teams can bypass these restrictions to achieve persistence or escalate privileges. This section explores techniques to modify or bypass TCC entries, focusing on authorized testing scenarios.


Modifying TCC Database Entries

The TCC database is stored in ~/Library/Preferences/com.apple.TCC.plist (a user-specific file) and managed via the tccutil command-line tool. Direct modification requires specific tools or elevated privileges to avoid system instability.

Using tccutil to Reset Entries

The tccutil tool can reset specific application entries, effectively revoking access permissions. For example:

tccutil reset "com.apple.TextEdit"
This command removes the application's access to sensitive resources, forcing re-prompting on subsequent use. Note that tccutil typically does not require sudo for standard operations, though elevated privileges may be needed for certain user-specific changes.

Manually Editing the TCC Database

The TCC database is a property list (plist) file. Use plutil to edit entries:

plutil -e ~/Library/Preferences/com.apple.TCC.plist
This opens the file in a text editor, allowing manual adjustments to access flags. For instance, removing an entry for a specific application can bypass its restrictions.


Bypassing TCC via Code Execution

Applications can bypass TCC by leveraging code execution to manipulate the database indirectly.

Using osascript to Execute AppleScript

AppleScript can interact with system processes to reset TCC entries:

tell application "System Events"
    do shell script "tccutil reset \"com.apple.TextEdit\""
end tell
This script executes the tccutil command without elevated privileges, bypassing user consent prompts in controlled environments.

Launchd Agents for Persistent Bypass

Create a launchd agent to automate TCC resets at system startup:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>
    <string>com.example.tccbypass</string>
    <key>ProgramArguments</key>
    <array>
        <string>/bin/bash</string>
        <string>-c</string>
        <string>tccutil reset "com.apple.TextEdit"</string>
    </array>
    <key>RunAtLoad</key>
    <true/>
</dict>
</plist>
Save this as ~/Library/LaunchAgents/com.example.tccbypass.plist and load it with launchctl load.


Advanced Techniques

Kernel Exploits for TCC Bypass

Kernel-level exploits are hypothetical examples and not standard methods for TCC bypass. Advanced techniques requiring deep system knowledge and privilege escalation vulnerabilities may exist but are not documented as standard practices.

Third-Party Tools for Automation

Tools like TCCBypass (a hypothetical example) automate TCC entry manipulation by parsing and modifying the plist file programmatically. These tools are illustrative of potential automation strategies but do not represent actual software. Real-world tools would require root access and careful implementation to avoid system instability.


Mitigation Strategies

  1. Regular Audits: Monitor TCC database changes using tools like tccutil list to detect unauthorized modifications.
  2. Application Sandboxing: Restrict applications to sandboxed environments to limit their ability to modify TCC entries.
  3. Least Privilege: Ensure applications run with minimal privileges to reduce the impact of TCC bypasses.
  4. System Integrity Protection (SIP): Enable SIP to prevent unauthorized modifications to critical system files, including the TCC database.

Key takeaways

  • The TCC database is a critical target for bypassing macOS access controls.
  • Tools like tccutil and manual plist edits can reset or modify entries, but require elevated privileges in specific scenarios.
  • Code execution via AppleScript or launchd agents enables persistent bypasses.
  • Advanced techniques like kernel exploits or third-party tools offer deeper control but carry higher risks.
  • Mitigation requires regular audits, sandboxing, and enforcing least privilege principles.