mirror of
https://github.com/moonD4rk/HackBrowserData.git
synced 2026-08-15 23:50:19 +02:00
Mirror the abe_embed treatment of the Windows ABE payload (#575) for the macOS CVE-2025-24204 securityd-dump path: retag gcoredump_darwin.go under 'darwin && keychain_gcore' and add a 'darwin && !keychain_gcore' stub for DecryptKeychainRecords. The default go build (and library consumers) then ship without the exploit code or its byte signatures; the capability is opt-in via -tags keychain_gcore, exactly like -tags abe_embed. GcoredumpRetriever already treats a DecryptKeychainRecords error as a silent fallthrough to the next tier, so the default build falls through to the native security-CLI path with no behavior change.