Experts claim to have found more weaknesses in Apple’s Gatekeeper tool, but it doesn’t seem too bothered


  • Researchers show Gatekeeper can be bypassed by replacing a previously running legitimate macOS app with malware
  • The attack requires code to be executed at the user level first and then passed into a malicious application that Gatekeeper will not double-check.
  • Apple dismissed the issue, saying locally rebuilt bundles were outside Gatekeeper’s scope, leaving the risk to social engineering.

Two researchers claim to have found a way to bypass Gatekeeper, a security feature built into macOS that helps protect users from running malicious or untrustworthy software. However, Apple doesn’t really see it that way and has apparently decided not to pursue the subject further.

Gatekeeper’s modus operandi is rather simple: when a user downloads an application outside of the App Store, it verifies that the product comes from an identified developer and is notarized by Apple. If it can’t verify it, it won’t allow it to run on the machine.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top