logoalt Hacker News

jwatzmanlast Thursday at 4:56 PM0 repliesview on HN

No — the victim app is code signed and the permissions and keychain access are tied to the cryptographic identity used to code sign. Replacing or wrapping or whatever here must happen with a different cryptographic identity (unless you actually exploit the victim app itself which is a whole different thing).