• Sources: primary, discussion
  • Summary: Kevin Kessler published on 2026-09-24 that macOS creates the CDC-ACM device node /dev/cu.usbmodem* readable and writable by any process, with no TCC prompt and no entitlement. Chained with an HID keyboard interface on the same USB composite device, he reports a 24-second exfiltration of SSH keys, AWS, GCP, Azure and Kubernetes credentials, keychain metadata and environment secrets from an unlocked Mac with no consent sheet shown, tested on macOS 26.4.1 on Apple Silicon with roughly 20 dollars of parts. He separately reports that a composite device plugged into a previously approved hub enumerates on a locked Mac with Lockdown Mode on, because macOS does not re-prompt downstream of an approved hub, which makes a one-time hub approval a persistent enumeration exemption.
  • Why it matters: Apple declined the report on 2026-05-20 as no identified security issue and left the 2026-05-21 rebuttal unanswered for four months, so this researcher-reported credential-theft path over USB has no vendor fix pending and no CVE assigned.
  • Follow-up: Track the pending MITRE CNA-LR request for a CVE, and whether Apple reopens case OE11057041574014 or extends TCC to serial device nodes.

send feedback on this story