Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Defense: Kernel Panic on macOS 10.15.1 with 3.3.3.35 Sensor

CB Defense: Kernel Panic on macOS 10.15.1 with 3.3.3.35 Sensor

Environment

  • CB Defense PSC Sensor: 3.3.3.35
  • Apple macOS: 10.15.1 (Catalina)

Symptoms

  • Kernel Panic (KP) at boot time
  • KP file generated (*.panic)
    /Library/Logs/DiagnosticReports
  • Putting Sensor in Bypass has no impact (on further testing)

Cause

Kernel Panics on macOS 10.15.1 when the Carbon Black Cloud Sensor is Installed
  • Under investigation in concert with AppleCare Support
  • Apple Enterprise team encourages Mac Enterprise customers to open an AppleCare Support case immediately
    Carbon Black/Apple Feedback #: FB7418712

Resolution

This issue is fixed with the 3.3.4.6 Sensor and higher, as well as with macOS 10.5.2 and higher.

Temporary Workaround
  1. Boot the endpoint to the Recovery Partition (or to Internet Recovery if a local Recovery Partition is unavailable) by holding Command + R
  2. Use Disk Utility to mount System volume if not yet mounted
  3. Close Disk Utility and launch Terminal, then type out the following command
    rm -rf /Volumes/<VOLUME_NAME>/Library/Extensions/CbDefenseSensor.kext
  4. Reboot endpoint to its boot partition

Related Content


Was this article helpful? Yes No
75% helpful (3/4)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
3006
Contributors