macOS Apps Vulnerable to Silent Replacement by Malware

macOS Apps Vulnerable to Silent Replacement by Malware

First seen 24 Jul 2026, 16:19 UTC News.YcombinatorTheregisterAppleinsider 74% similarity 51.9

Article Content

Browse articles
ThreatCluster

Researchers Talal Haj Bakry and Tommy Mysk discovered a vulnerability in macOS that allows attackers to silently replace the main executable of trusted applications downloaded from the web without requiring elevated privileges. This exploit occurs after the app has been run once, allowing Gatekeeper to validate it as trusted. The attack method involves archiving the app, deleting the original, and extracting the archive, which bypasses macOS's security checks. While the vulnerability does not affect apps from the Mac App Store, it poses a significant risk to widely used applications like Signal, Slack, and Visual Studio Code. Apple has been informed but has deemed it a low priority issue, suggesting that it relies on social engineering rather than a direct bypass of security mechanisms. The researchers emphasize that the exploit requires prior code execution as the current user, typically through a malicious app or script. The current status indicates that while the vulnerability exists, it is not being actively exploited in the wild.

Key Points: • macOS apps downloaded from the web can be silently replaced with malicious versions. • The exploit requires prior code execution as the current user, often through a malicious app. • Apple has acknowledged the issue but considers it a low priority, focusing on user behavior.

ThreatCluster AI

Timeline

2026-07-23
Vulnerability in macOS discovered
Researchers revealed a flaw allowing silent replacement of app executables without elevated privileges.
News.Ycombinator
2026-07-24
Apple informed but unconcerned
Apple stated the vulnerability is not a significant threat, attributing it to social engineering.
Appleinsider
2026-07-24
Research findings published
The researchers published their findings, demonstrating the exploit and its implications for macOS security.
Theregister

Community

Browse all →