An approved USB hub silently authorizes a composite device that can run commands and export credentials from an unlocked Mac.
Affects
macOS on Apple-silicon Macs using an approved USB hub, dock, or multi-port adapter
The demonstrated path requires brief physical access to a free port on a previously approved hub and an unlocked Apple-silicon Mac.
Detail and 4 sources
The composite device inherited approval, injected Terminal commands and copied credentials to its flash in about 24 seconds.
With the Mac locked and Lockdown Mode enabled, the interfaces still enumerated, but locked-state execution was not demonstrated.
Chain to watch
Attach a composite HID and CDC-ACM device behind a previously approved hub→↓Confirm that both interfaces enumerate while the Mac is locked under Lockdown Mode→↓Test whether either accepted interface can produce execution or data access without unlocking→↓Whether locked-state interface enumeration can become command execution or data access without an unlock.
Unverified chainRetest representative Apple-silicon Macs and common docks with the screen locked, focusing on non-HID consumers of the accepted serial interface.
Physical placement and an unlocked session keep the demonstrated execution path below today’s remote leads.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.