Experts claim to have found more weaknesses in Apple's Gatekeeper tool but
it doesn't seem too bothered
Date:
Sat, 25 Jul 2026 14:20:00 +0000
Description:
Gatekeeper doesn't blink when you archive a legitimate app and replace it
with an evil doppelganger.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware Attack requires prior userlevel code execution, then swaps in a malicious app that Gatekeeper wont reverify Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeepers scope, leaving risk to social engineering A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesnt really see it that way and has seemingly decided not to pursue the issue further.
Gatekeepers modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it cant verify it - it wont allow it to run on the machine. Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper wont even blink its virtual eye. Latest Videos From TechRadar Watch full video here: Locally built That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).
Once that is obtained, they can archive a legitimate app, remove the
original, then replace it with malware , and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. You may like This new macOS infostealer poses as an
Apple crash reporting tool to try and steal all your valuable data Anthropic Mythos helped build a working macOS exploit in just five days Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be
After reporting the issue to Apple, the company apparently just closed it.
"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope." Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Via The Register The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weakne sses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)