1.94 APPL-14-002068

Information

The macOS system must secure user's home folders.

GROUP ID: V-259514RULE ID: SV-259514r991592

The system must be configured to prevent access to other user's home folders.

The default behavior of macOS is to allow all valid users access to the top level of every other user's home folder while restricting access only to the Apple default folders within.

Solution

Configure the macOS system to set the appropriate permissions for each user on the system with the following command:

IFS=$'\n'for userDirs in $( /usr/bin/find /System/Volumes/Data/Users -mindepth 1 -maxdepth 1 -type d ! ( -perm 700 -o -perm 711 ) | /usr/bin/grep -v "Shared" | /usr/bin/grep -v "Guest" ); do/bin/chmod og-rwx "$userDirs"doneunset IFS

See Also

https://workbench.cisecurity.org/benchmarks/24070