- Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware
- The attack requires pre-execution of user-level code and is then swapped into a malicious application that Gatekeeper will not re-verify
- Apple dismissed the issue and said that locally rebuilt packages fall outside the scope of Gatekeeper, leaving the risk of social engineering.
A pair of researchers claim to have found a way to bypass Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However, Apple doesn’t really see it that way and has apparently decided not to pursue the issue any further.
Gatekeeper’s modus operandi is quite simple: when a user downloads an app from outside the App Store, they verify that the product comes from an identified developer and is notarized by Apple. If you can’t verify it, you won’t allow it to run on the machine.
Now, security researchers Talal Haj Barky and Tommy Mysk say that as long as a legitimate app is run at least once on a macOS device, it can be replaced with a malicious version and Gatekeeper won’t even blink its virtual eye.
Latest videos ofTechnologyRadar
locally built
That also means that the attack is not so easy to perform. The threat actor must have a way to execute user-level code (for example, a malicious application, a compromised software package installed via a package manager, or a fast injection attack that tricks an AI agent).
Once obtained, they can archive a legitimate application, delete the original, and then replace it with malware, and Gatekeeper will not attempt to reauthorize it. That malicious version can trick the victim into further compromising the device, given that a certain level of trust has already been established.
After reporting the issue to Apple, the company apparently simply shut it down.
“Apple does not consider this attack to be ‘modifying’ the signed executable,” Mysk said. “Instead, Apple says that when you archive/restore the app package, the proof-of-concept code overwrites the entire app package, making it locally created. Locally created app packages are not covered by macOS guards. And that’s why access to Keychain or TCC protected directories requires system authorization requests. And whether users accept them is a matter of social engineering attacks that Apple considers out of scope.”
Through The Registry
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




