Application security

macOS Gatekeeper vulnerability allows app replacement

Open finder app in macOs

As detailed in The Register, security researchers uncovered a vulnerability in Apple's macOS Gatekeeper security feature that could allow malicious actors to replace legitimate applications with harmful versions.

Researchers Talal Haj Bakry and Tommy Mysk discovered a flaw in Gatekeeper's defenses that permits the main executable of a downloaded macOS application, once run, to be silently replaced by a malicious version without requiring elevated privileges. This bypass is possible for apps downloaded from the internet, but not for those from the Mac App Store. The attack requires the attacker to have a means of user-level code execution, such as a malicious app or script. The researchers demonstrated that by archiving and then replacing an app bundle, macOS does not re-prompt for authorization, even though Gatekeeper's initial validation is supposed to prevent such modifications. This could affect popular applications like Slack, Signal, and Visual Studio Code. While Apple has reportedly closed the issue, stating that overwriting the entire bundle makes it a locally built app not covered by macOS guards, the researchers argue that the core Gatekeeper validation mechanism is lax.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds