OS X Vulnerability Allows Cybercriminals to Bypass Gatekeeper Checks

Advertisement
By Manish Singh | Updated: 1 October 2015 16:39 IST

A security researcher has reported a very simple workaround that could let anyone bypass Gatekeeper, a security feature in OS X that safeguards the desktop operating system from running malware and other unwanted software by restricting the sources from which users can install applications downloaded from the Internet.

Patrick Wardle, the director of research at firm Synack said that a binary file that is already trusted by Apple needs no other verification to load and run potentially compromised system components or files.

Advertisement

In his testing, Wardle found that a signed Photoshop installer had no issues loading plugins from another directory -- the content of which were replaced with malware files. This happened without the program notifying the user. He also tested this with Apple-distributed programs, but declined to reveal the name to honour Apple's request.

Gatekeeper checks the digital certificate of a downloaded app to ensure that the developer or point of origination of the app is Apple-recognised. And the fact that it doesn't prevent applications that are already trusted by OS X from working in strange, undocumented ways - in this case tapping malicious components - is where lies the security flaw.

Advertisement

"If the application is valid--so it was signed by a developer ID or was (downloaded) from the Mac App Store--Gatekeeper basically says 'OK, I'm going to let this run,' and then Gatekeeper essentially exits," Wardle told Ars Technica. "It doesn't monitor what that application is doing. If that application turns around and either loads or executes other content from the same directory... Gatekeeper does not examine those files."

The vulnerability requires a user to download or copy and relaunch the modified software, he noted. But users should still be very cautious because attackers could target third-party signed applications and riddle them with malware over unencrypted downloads. Wardle said that he informed Apple about the vulnerability more than 60 days ago. The company told the publication that it is working on a patch.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Turbo 5 India Launch Roundup: Here's Everything That We Know So Far
  1. Kenatha Kanom OTT Release Date: Yogi Babu’s Satirical Drama to Arrive on JioHotstar
  2. Ab Hoga Hisaab OTT Release: When and Where to Watch It Online?
  3. Astronomers Discover Why Massive Galaxies Died Early in the Universe
  4. Akshay Kumar’s Bhooth Bangla Out on OTT: Know Where to Stream This Horror-Comedy Online
  5. House Of The Dragon Season 3 OTT Release Date: When and Where to Watch it Online?
  6. Raakh Now Streaming Online: Where to Watch This Ali Fazal’s Investigative Thriller Series
  7. The East Palace OTT Release Date: Know When and Where to Watch it Online
  8. Starlink Constellation Crosses 10,600 Satellites After Latest SpaceX Launch
  9. WhatsApp Could Soon Offer Meta One Plus, Meta One Premium Subscriptions With Additional Features
  10. Honor Tipped to Launch Smartphone With 10,000-Nit Display and 10,000mAh Battery
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.