Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaemon.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Undercover | Orbicule | * | * |