My Mac Was a $2000 Brick. Here's How I Gained Root Access in 5 Minutes
I built https://github.com/0xwi11iam/macos-evilmaid to help those who are locked out of their Macs. With this tool, with just a USB drive and Recovery Mode you can regain root access to your Mac in under 5 minutes witho
I built https://github.com/0xwi11iam/macos-evilmaid to help those who are locked out of their Macs.
With this tool, with just a USB drive and Recovery Mode you can regain root access to your Mac in under 5 minutes without deleting any files and not touching ANYTHING that might damage your system.
I remember the exact moment I realized I was stuck.
I was sitting in front of my own Macβa machine I paid for with my own moneyβand I couldn't do anything with it. I had standard user permissions. No sudo. No admin access. No way to install the tools I needed. No way to fix the problem.
It wasn't malicious. It wasn't stolen. It was just... locked down. MDM. A provisioning profile from an organization that had long since forgotten I existed. And I was trapped in my own hardware.
I spent days trawling through forums, GitHub issues, and ancient StackExchange threads. Everything I found was either: completely outdated (10.12 Sierra-era fixes that no longer work), dangerously destructive (suggestions to wipe the entire drive), or vague and unhelpful ("just use Recovery Mode" with no actual steps).
I was stuck in a dead zoneβa technical problem that was just obscure enough that nobody had written a clear, modern, working solution.
So I built one.
This is macos-evilmaid β a tool that lets you regain root access on an MDM-locked Mac in under 5 minutes, using nothing more than a USB drive and Recovery Mode.
Here's what it does:
- You boot into Recovery Mode (β+R or power button on Apple Silicon).
- You run build.sh from a USB drive.
- The script drops a LaunchDaemon that runs as root on the next boot.
- You connect to the resulting reverse shell via nc.
- You enable the root user with dsenableroot.
- You're done. Full admin access. No files deleted. No data lost.
It works on macOS Sequoia (untested on Tahoe, but likely compatible). It targets the data volume (/private/var/tmp/ and /Library/LaunchDaemons/), so it doesn't break the system volume seal.
But I didn't just release a script. I documented everything:
- The attack chainβso you understand what's happening under the hood.
- The mitigationsβso you can harden your own systems against this.
- The detection methodsβso blue teams know what to look for.
- The ethical boundariesβso there's no confusion about when this is legal and when it's not.
This is the tool I wished existed a year ago. I built it so nobody else has to waste days searching for a fix that doesn't exist.
Thanks!
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.