OS X Vulnerability Allows Cybercriminals to Bypass Gatekeeper Checks

Advertisement
By Manish Singh | Updated: 1 October 2015 16:39 IST
OS X Vulnerability Allows Cybercriminals to Bypass Gatekeeper Checks

A security researcher has reported a very simple workaround that could let anyone bypass Gatekeeper, a security feature in OS X that safeguards the desktop operating system from running malware and other unwanted software by restricting the sources from which users can install applications downloaded from the Internet.

Patrick Wardle, the director of research at firm Synack said that a binary file that is already trusted by Apple needs no other verification to load and run potentially compromised system components or files.

In his testing, Wardle found that a signed Photoshop installer had no issues loading plugins from another directory -- the content of which were replaced with malware files. This happened without the program notifying the user. He also tested this with Apple-distributed programs, but declined to reveal the name to honour Apple's request.

Gatekeeper checks the digital certificate of a downloaded app to ensure that the developer or point of origination of the app is Apple-recognised. And the fact that it doesn't prevent applications that are already trusted by OS X from working in strange, undocumented ways - in this case tapping malicious components - is where lies the security flaw.

Advertisement

"If the application is valid--so it was signed by a developer ID or was (downloaded) from the Mac App Store--Gatekeeper basically says 'OK, I'm going to let this run,' and then Gatekeeper essentially exits," Wardle told Ars Technica. "It doesn't monitor what that application is doing. If that application turns around and either loads or executes other content from the same directory... Gatekeeper does not examine those files."

The vulnerability requires a user to download or copy and relaunch the modified software, he noted. But users should still be very cautious because attackers could target third-party signed applications and riddle them with malware over unencrypted downloads. Wardle said that he informed Apple about the vulnerability more than 60 days ago. The company told the publication that it is working on a patch.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. BSNL Announces Flash Sale in India With Free Data, Discounts
  2. Vivo X200 FE India Launch Teased; Key Specifications Revealed
  3. Samsung Galaxy M36 5G Launching Today: All You Need to Know
  4. Nothing Phone 3 Renders Leaked Ahead of July 1 Launch
  5. OTT Releases of the Week: Squid Game S3, Raid 2, Panchayat S4, and More
  6. Samsung Galaxy M36 5G Launched in India: Price, Specifications
  7. Here Are The Best Deals of Steam Summer Sale 2025
  8. Xiaomi YU7 Electric SUV Sale in China Begins at This Price
  9. Redmi K Pad With 8.8-Inch Display, 7,500mAh Battery Unveiled: See Details
  1. James Webb Telescope Detects Methanol and Ethanol Near Young Stars, Hinting at Life’s Origins
  2. Rubin Observatory Captures Distant Nebulae From Chilean Mountaintop
  3. Apple to Expand Swift Language Support to Android; Sets Up Android Working Group
  4. FBC: Firebreak Has Crossed One Million Players, Remedy Confirms
  5. Two Spacecraft Recreate Artificial Solar Eclipses to Observe the Sun’s Superhot Corona
  6. Honor Magic V5's Periscope Telephoto Camera Teased Ahead of July 2 Launch
  7. Breakthrough Laser Tech Enhances LiDAR Accuracy and Gas Detection
  8. Canva Launches Deep Research Connector with ChatGPT, Introduces New Open MCP Server
  9. Samsung Galaxy S26 Series Said to Offer More RAM; iPhone 17 Lineup May Get 12GB RAM
  10. Meta Reportedly Planning to Acquire Startup PlayAI and Some of Its Employees
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.