The macOS system must disable iPhone Mirroring.

STIG ID: APPL-15-002271  |  SRG: SRG-OS-000080-GPOS-00048 |  Severity: medium |  CCI: CCI-000213,CCI-000381,CCI-001443 |  Vulnerability Id: V-272477

Vulnerability Discussion

iPhone Mirroring must be disabled to prevent file transfers to or from unauthorized devices.

Disabling iPhone Mirroring also prevents potentially unauthorized applications from appearing as if they are installed on the Mac.

Satisfies: SRG-OS-000080-GPOS-00048, SRG-OS-000095-GPOS-00049, SRG-OS-000300-GPOS-00118

Check

Verify the macOS system is configured to disable iPhone Mirroring with the following command:

/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\
.objectForKey('allowiPhoneMirroring').js
EOS

If the result is not "false", this is a finding.

Fix

Configure the macOS system to disable iPhone Mirroring by installing the "com.apple.applicationaccess" configuration profile.