- Researchers show that Gatekeeper can be bypassed by replacing a previously running legitimate macOS app with malware
- Attack requires prior execution of user-level code and then swaps in a malicious app that Gatekeeper won’t re-authenticate
- Apple denied the issue, saying that locally rebuilt bundles fall outside Gatekeeper’s scope, leaving a risk of social engineering
A pair of researchers claim to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. But Apple doesn’t really see it that way and has apparently decided not to pursue the issue further.
Gatekeeper’s modus operandi is quite simple – when a user downloads an app outside the App Store, it verifies that the product comes from an identified developer and is notarized by Apple. If it can’t confirm that – it won’t allow it to run on the machine.
Now, security researchers Talal Haj Barky and Tommy Mysk claim that as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version and Gatekeeper won’t even blink its virtual eye.
Latest videos fromTechRadar
Locally built
It also means that the attack is not as straightforward to execute. The threat actor must have a way to execute user-level code (eg, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).
Once that’s accomplished, they can archive a legitimate app, remove the original, and then replace it with malware, and Gatekeeper won’t try to reauthorize it. The malicious version can then trick the victim into compromising the device even more since a certain level of trust was already established.
After reporting the issue to Apple, the company apparently just shut it down.
“Apple does not consider this attack to ‘modify’ the signed executable,” Mysk said. “Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And that’s why accessing Keychain or TCC-protected folders requires system authentication prompts. And for users to accept these attacks, Apple’s social engineering is a matter of social engineering.”
Via The register
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



