elastic / elastic/endpoint

All macOS Elastic Endpoint versions affected by macOS 13 (Ventura) Full Disk Access bug

Open
#33 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Swift
Stars
47
Forks
9
PR merge metrics
No merged PRs in 30d

Description

All versions of Elastic Endpoint are affected by a [bug](https://developer.apple.com/documentation/macos-release-notes/macos-13_1-release-notes) in macOS 13 (Ventura) which disables previously granted Full Disk Access. This bug does not affect Elastic Endpoints managed by an MDM solution.

Steps to reproduce:
* Install Elastic Endpoint on macOS 12 (Monterey) without MDM
* Follow [these](https://www.elastic.co/guide/en/security/current/deploy-elastic-endpoint.html) steps to grant all permissions needed
* See that after approval Endpoint's status in the Security App's Endpoint page is HEALTHY
* Upgrade to macOS 13 (Ventura)
* See that Endpoint's status in the Security App is is now UNHEALTHY because Full Disk Access is no longer approved

Workaround
* In Settings -> Security & Privacy -> Privacy -> Full Disk Access, remove Full Disk Access approval from `ElasticEndpoint` and `co.elastic.systemextension`
* Re-enable Full Disk Access in the same location. A reboot may be required between these two steps.

This bug is in macOS not Elastic Endpoint. It will be fixed by an update to macOS.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.