Nullcon Goa 2025: Draining Your Credentials From Popular MacOS Password Managers - Wojciech Regula
About this talk
This talk explores the macOS hardened runtime, sandboxing, and TCC app management privileges, providing insights into their workings. The speaker discusses various vulnerabilities, including zero-day vulnerabilities and architectural flaws found in popular macOS password managers. Additionally, the session delves into the security aspects of software distribution, highlighting instances where applications from websites can be more secure than those from the Apple Mac App Store, supported by demonstrations and exploit examples.
More from this event
See all 30 talks →
Nullcon Goa 2025: Securing the chains: Building defensive layers for software supply chains
38:14
Nullcon Goa 2025 | Large-Scale Exposure Of Orphaned Commits On Major Git Platforms by Kumar Ashwin
26:30
Nullcon Goa 2025 | Panel: Modernizing Security Architecture: Platforms or Best-of-Breed, What Works?
44:47
Nullcon Goa 2025: Panel | Cyber Fusion Center: The Command Center For Integrated Cyber Defense
42:01