Skip to main content

Researcher finds exploit to bypass OS X’s Gatekeeper security

researcher finds exploit to bypass os xs gatekeeper security apple macbook pro 13 ret 2015 lidlogo
Bill Roberson/Digital Trends
There’s an old myth that Macs are invulnerable to malware.  This was never really the case, and is certainly quite false today — as evidenced by a new exploit discovered by researchers that could render the operating system’s Gatekeeper security package.

First introduced in 2012, Gatekeeper is Apple’s proprietary method of keeping Macs safe and secure. It’s a handy, pre-installed program that can differentiate between legitimate programs and applications that have been tampered with, as well as helping users steer clear of nuisance software like Trojans and key-loggers.

However, a security researcher has now found a simple method of counteracting the program and bypassing its defences, according to a report from Ars Technica. This exploit uses a trusted binary file to avoid the program’s security measures, which allows for malicious code housed in the same folder to run successfully following the check.

The site spoke to Patrick Wardle, director of research for security firm Synack, who stated that this is a problem with the very design of Gatekeeper. The validity of the application is the only thing that the program checks, so if that’s given the OK, other code can run relatively easily.

Wardle goes on to suggest that the exploit can be carried out simply by downloading a widely available binary, renaming it, and then pairing it with the desired malicious code rather than its typical partner. This information has already been submitted to Apple, and it’s under the company’s request that the specific binary goes unnamed.

A representative of Apple has confirmed that a patch in in development by the company, although at present there’s no timeline on when it will be made available to users. Wardle will present his findings this week at the Virus Bulletin Conference in Prague.

Editors' Recommendations

Brad Jones
Former Digital Trends Contributor
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
The Apple M1X may not be called ‘M1X’ at all
Apple M1 chip on a motherboard.

Update: As was announced at the Apple Unleashed event, this rumor about the M1 Pro and M1 Max turned out to be true.

Apple's hotly-anticipated M1X chip may not be called the "M1X" at all. App logs have revealed names like "M1 Pro" and "M1 Max," suggesting that Apple is taking a different approach to naming with its M1 refresh. We'll know in a few short hours, with Apple's Unleashed event going live shortly.

Read more
Oppo’s Android 12-based ColorOS 12 is coming to the Find X3 Pro in December
oppo find x3 pro review back hand

ColorOS 12, Oppo’s smartphone operating system based on Google’s Android 12, will be coming to the Oppo Find X3 Pro in December, with other models in the company’s range to follow over the coming year. Oppo says the new version is cleaner, smoother, and more inclusive than before, but if you’re waiting to hear a mass of new features, you may be disappointed.

Inclusivity is one of the key aspects of ColorOS 12, and is important to the continued growth of ColorOS around the world. New Omoji animated emoji characters have a wide range of customizations to ensure they appeal to everyone, for example, but it’s in the software itself that a lot of work has taken place to make it more inclusive. This includes formatting and appearance changes for text in languages other than Chinese and English, new translations for specific languages including Danish, where Oppo understood it was lacking, and even alterations to the camera app algorithm in the beautification feature to make it more suitable for more people.

Read more
Where’s the M1X MacBook Pro? Here’s why Apple skipped the announcement
Macbook Electric Color

Apple's "California Streaming" event just ended, and it was exactly what we thought it would be. The iPhone 13, the Apple Watch Series 7, and even some new iPads.

That's plenty for one Apple event, no doubt, but it did leave out one highly-anticipated product that we've been waiting for since WWDC. The M1X MacBook Pro.
When's it coming?

Read more