CVE-2020-9771 is a macOS privacy and authorization bypass affecting APFS snapshot mounting on Catalina and Mojave. A local low-privileged user could create or use existing local APFS snapshots and mount them read-only with the noowners behavior, causing files in the mounted snapshot to be exposed as readable by the current effective user. This allowed access to other users’ files and to data normally protected by Transparency, Consent, and Control, including protected areas of the file system. Technical analysis attributes the flaw to a missing authorization check in the snapshot-mount path: prior to Apple’s fix, APFS snapshot mounting reached the mount logic without a dedicated Mandatory Access Control Framework or Sandbox policy check for snapshot mounts. Apple later introduced a new snapshot-mount entitlement and a MACF hook, mac_mount_check_snapshot_mount, to enforce authorization for this operation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A macOS/APFS-related exploit referenced as a dated bypass technique that AmnesiaStealer attempts to use for Safari cookie theft when other methods fail.
A macOS TCC bypass vulnerability used here as a referenced technique to steal Safari cookies on macOS Catalina systems.
An older macOS Transparency, Consent, and Control (TCC) bypass used by the malware to access Safari cookies and the TCC database.
A macOS vulnerability referenced as part of AmnesiaStealer's attempted TCC bypass chain using APFS snapshots and mount_apfs; the article states these attempts fail on macOS 26.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.