Appleinsider
macOS Apps Vulnerable to Silent Replacement by Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers Talal Haj Bakry and Tommy Mysk discovered a vulnerability in macOS that allows attackers to silently replace the main executable of trusted applications downloaded from the web without requiring elevated privileges. This exploit occurs after the app has been run once, allowing Gatekeeper to validate it as trusted. The attack method involves archiving the app, deleting the original, and extracting the archive, which bypasses macOS's security checks. While the vulnerability does not affect apps from the Mac App Store, it poses a significant risk to widely used applications like Signal, Slack, and Visual Studio Code. Apple has been informed but has deemed it a low priority issue, suggesting that it relies on social engineering rather than a direct bypass of security mechanisms. The researchers emphasize that the exploit requires prior code execution as the current user, typically through a malicious app or script. The current status indicates that while the vulnerability exists, it is not being actively exploited in the wild.
Key Points: • macOS apps downloaded from the web can be silently replaced with malicious versions. • The exploit requires prior code execution as the current user, often through a malicious app. • Apple has acknowledged the issue but considers it a low priority, focusing on user behavior.