- Researchers show Gatekeeper can be bypassed by replacing a previously running legitimate macOS app with malware
- The attack requires code to be executed at the user level first and then passed into a malicious application that Gatekeeper will not double-check.
- Apple dismissed the issue, saying locally rebuilt bundles were outside Gatekeeper’s scope, leaving the risk to social engineering.
Two researchers claim to have found a way to bypass Gatekeeper, a security feature built into macOS that helps protect users from running malicious or untrustworthy software. However, Apple doesn’t really see it that way and has apparently decided not to pursue the subject further.
Gatekeeper’s modus operandi is rather simple: when a user downloads an application outside of the App Store, it verifies that the product comes from an identified developer and is notarized by Apple. If it can’t verify it, it won’t allow it to run on the machine.
Now, security researchers Talal Haj Barky and Tommy Mysk say that as long as a legitimate app has been run at least once on a macOS device, it can be replaced by a malicious version, and Gatekeeper doesn’t even blink its virtual eyes.
Latest videos fromTechRadar
Built locally
This also means that the attack is not that simple to carry out. The malicious actor must have a way to execute code at the user level (for example, a malicious application, a compromised software package installed via a package manager, or a rapid injection attack that fools an AI agent).
Once this is achieved, they can archive a legitimate application, delete the original, then replace it with malware, and Gatekeeper will not attempt to reauthorize it. This malicious version can then encourage the victim to further compromise the device, since a certain level of trust has already been established.
After reporting the issue to Apple, the company apparently just shut it down.
“Apple does not consider this attack to be a ‘modification’ of the signed executable,” Mysk said. “Instead, Apple claims that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS protections. And that’s why accessing keychain or TCC-protected directories requires system permission prompts. And for users, accepting those is a matter of attacks of social engineering that Apple considers out of reach.
Via The register
The best antivirus for every budget
Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.




