New macOS Exploits: macSubstrate and MacOSThreatTrack Tools Released

New macOS Exploits: macSubstrate and MacOSThreatTrack Tools Released

First seen 9 Sep 2026, 14:14 UTC Sploitus 27.0

Article Content

Browse articles
ThreatCluster

Two new tools targeting macOS systems have been released: macSubstrate, a code injection tool for runtime modifications, and MacOSThreatTrack, a security reconnaissance tool for threat detection. macSubstrate allows users to inject plugins into macOS applications, including sandboxed ones, potentially bypassing System Integrity Protection (SIP). MacOSThreatTrack enhances security monitoring by collecting extensive system and user data to detect malicious activities. Both tools are designed for advanced users and developers, with macSubstrate requiring SIP to be disabled for full functionality. Users are advised to exercise caution when installing plugins from untrusted sources. The tools are available under the MIT license, promoting community contributions and enhancements.

Key Points: • macSubstrate enables code injection into macOS apps, including sandboxed applications. • MacOSThreatTrack provides comprehensive security monitoring and threat detection capabilities. • Both tools require careful handling to avoid security risks associated with untrusted plugins.

Ask AI about this cluster

Timeline

2026-09-09
macSubstrate tool released
macSubstrate allows code injection into macOS applications, potentially bypassing SIP protections.
Sploitus
2026-09-09
MacOSThreatTrack tool released
MacOSThreatTrack is designed for proactive threat detection and system information gathering on macOS.
Sploitus