Security researchers Talal Haj Barky and Tommy Mysk discovered a method to bypass macOS Gatekeeper by replacing previously authorized applications with malicious versions that evade further security verification.
Key Points
- Researchers Talal Haj Barky and Tommy Mysk identified a vulnerability where Gatekeeper fails to re-verify macOS applications after they are replaced by malicious files.
- The attack requires an initial stage of user-level code execution to archive and swap legitimate app bundles with malicious counterparts.
- Apple declined to address the issue, stating that locally rebuilt app bundles fall outside the scope of Gatekeeper’s security protections.
- The company maintains that risks involving user authorization prompts for Keychain or TCC access are considered social engineering rather than security flaws.