OS X Vulnerability Allows Cybercriminals to Bypass Gatekeeper Checks

Advertisement
By Manish Singh | Updated: 1 October 2015 16:39 IST

A security researcher has reported a very simple workaround that could let anyone bypass Gatekeeper, a security feature in OS X that safeguards the desktop operating system from running malware and other unwanted software by restricting the sources from which users can install applications downloaded from the Internet.

Patrick Wardle, the director of research at firm Synack said that a binary file that is already trusted by Apple needs no other verification to load and run potentially compromised system components or files.

Advertisement

In his testing, Wardle found that a signed Photoshop installer had no issues loading plugins from another directory -- the content of which were replaced with malware files. This happened without the program notifying the user. He also tested this with Apple-distributed programs, but declined to reveal the name to honour Apple's request.

Gatekeeper checks the digital certificate of a downloaded app to ensure that the developer or point of origination of the app is Apple-recognised. And the fact that it doesn't prevent applications that are already trusted by OS X from working in strange, undocumented ways - in this case tapping malicious components - is where lies the security flaw.

Advertisement

"If the application is valid--so it was signed by a developer ID or was (downloaded) from the Mac App Store--Gatekeeper basically says 'OK, I'm going to let this run,' and then Gatekeeper essentially exits," Wardle told Ars Technica. "It doesn't monitor what that application is doing. If that application turns around and either loads or executes other content from the same directory... Gatekeeper does not examine those files."

The vulnerability requires a user to download or copy and relaunch the modified software, he noted. But users should still be very cautious because attackers could target third-party signed applications and riddle them with malware over unencrypted downloads. Wardle said that he informed Apple about the vulnerability more than 60 days ago. The company told the publication that it is working on a patch.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here are the Best Phones for Portrait Photography in India in 2026
  1. Japan Digital Agency Reports Potential Leak of 246,000 Records After Cyberattack
  2. Samsung Galaxy SmartTag 3 Design, Colourways and Price Leaked Online
  3. Denmark Central Bank Flags Risks as Stablecoin Market Expands
  4. Google Makes It Easier to Switch Password Managers on Android: How to Transfer Passwords and Passkeys
  5. Instagram Lets Users Add Tagged Posts to Their Main Profile Grid
  6. BGMI 4.6 Update Set to Arrive on September 16 With Supernatural Midnight Hunters Theme Mode
  7. India Adopts Digital Rupee for Bond Transaction Settlements
  8. iQOO 16 Design, Colourway Revealed as Firm Confirms Major Camera Upgrade
  9. AMD Ryzen 7500 and Ryzen 5 5500F Desktop Processors Launched: Specifications, Features
  10. Snapdragon 8 Elite Extreme Gen 6 Outperforms MediaTek’s Upcoming Flagship Smartphone Chipset
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.