Experts claim to have found several weaknesses in Apple’s Gatekeeper tool – but it doesn’t seem too bothered


  • Researchers show that Gatekeeper can be bypassed by replacing a previously running legitimate macOS app with malware
  • Attack requires prior execution of user-level code and then swaps in a malicious app that Gatekeeper won’t re-authenticate
  • Apple denied the issue, saying that locally rebuilt bundles fall outside Gatekeeper’s scope, leaving a risk of social engineering

A pair of researchers claim to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. But Apple doesn’t really see it that way and has apparently decided not to pursue the issue further.

Gatekeeper’s modus operandi is quite simple – when a user downloads an app outside the App Store, it verifies that the product comes from an identified developer and is notarized by Apple. If it can’t confirm that – it won’t allow it to run on the machine.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top