Experts claim to have found more weaknesses in Apple’s Gatekeeper tool, but they don’t seem to worry them too much.



  • Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware
  • The attack requires pre-execution of user-level code and is then swapped into a malicious application that Gatekeeper will not re-verify
  • Apple dismissed the issue and said that locally rebuilt packages fall outside the scope of Gatekeeper, leaving the risk of social engineering.

A pair of researchers claim to have found a way to bypass Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However, Apple doesn’t really see it that way and has apparently decided not to pursue the issue any further.

Gatekeeper’s modus operandi is quite simple: when a user downloads an app from outside the App Store, they verify that the product comes from an identified developer and is notarized by Apple. If you can’t verify it, you won’t allow it to run on the machine.

Leave a Comment

Your email address will not be published. Required fields are marked *