This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may be able to modify protected parts of the file system.
https://support.apple.com/en-us/121570
https://support.apple.com/en-us/121568
https://support.apple.com/en-us/121564
http://seclists.org/fulldisclosure/2024/Oct/13