From 500c95c86c2b1808f25c51756b18c1a360047e2b Mon Sep 17 00:00:00 2001 From: David Rogers <120214987+drogers0@users.noreply.github.com> Date: Thu, 6 Aug 2026 21:25:04 -0500 Subject: [PATCH] refactor(darwin): make keychain gcore dump opt-in via build tag (#629) Mirror the abe_embed treatment of the Windows ABE payload (#575) for the macOS CVE-2025-24204 securityd-dump path: retag gcoredump_darwin.go under 'darwin && keychain_gcore' and add a 'darwin && !keychain_gcore' stub for DecryptKeychainRecords. The default go build (and library consumers) then ship without the exploit code or its byte signatures; the capability is opt-in via -tags keychain_gcore, exactly like -tags abe_embed. GcoredumpRetriever already treats a DecryptKeychainRecords error as a silent fallthrough to the next tier, so the default build falls through to the native security-CLI path with no behavior change. --- masterkey/gcoredump_darwin.go | 2 +- masterkey/gcoredump_stub_darwin.go | 17 +++++++++++++++++ 2 files changed, 18 insertions(+), 1 deletion(-) create mode 100644 masterkey/gcoredump_stub_darwin.go diff --git a/masterkey/gcoredump_darwin.go b/masterkey/gcoredump_darwin.go index 1ad21c2..d426446 100644 --- a/masterkey/gcoredump_darwin.go +++ b/masterkey/gcoredump_darwin.go @@ -1,4 +1,4 @@ -//go:build darwin +//go:build darwin && keychain_gcore package masterkey diff --git a/masterkey/gcoredump_stub_darwin.go b/masterkey/gcoredump_stub_darwin.go new file mode 100644 index 0000000..def8d81 --- /dev/null +++ b/masterkey/gcoredump_stub_darwin.go @@ -0,0 +1,17 @@ +//go:build darwin && !keychain_gcore + +package masterkey + +import ( + "errors" + + "github.com/moond4rk/keychainbreaker" +) + +// DecryptKeychainRecords returns an error in default builds so GcoredumpRetriever +// falls through silently to the next tier. The CVE-2025-24204 securityd-dump +// implementation (gcoredump_darwin.go) is only compiled with -tags keychain_gcore, +// keeping the default `go build` free of the exploit code and its byte signatures. +func DecryptKeychainRecords() ([]keychainbreaker.GenericPassword, error) { + return nil, errors.New("keychain gcore dump not built in (rebuild with -tags keychain_gcore)") +}