Skip to main content
  1. Home
  2. Computing
  3. News

Apple mistakenly verified a macOS malware

Add as a preferred source on Google

A malware Mac package slipped past Apple’s verification process, a new report finds. As per security researcher, Patrick Wardle, Apple inadvertently approved a malicious desktop app that was disguised as an Adobe Flash installer to trick users.

Apple allows Mac users to install apps from sources outside of its own App Store. However, to ensure this policy doesn’t end up infesting Macs with viruses and malware, the company has a process called “notarization” that scans apps for security issues. Developers are required to submit their code prior to distribution for approval. If an app is unable to get past this verification stage, it is automatically blocked by Mac’s built-in screening program, Gatekeeper — irrespective of where it was downloaded from.

Recommended Videos

Wardle discovered that a popular malware called Shlayer, which security firm Kaspersky labeled as the most common threat that Macs faced in 2019, featured snippets of code that were officially notarized by Apple. Therefore, if someone downloaded and tried to run this on their Mac, they wouldn’t be alerted through any warnings. Shlayer is an adware that can intercept your web traffic and replace the webpages you try to load with its own malicious ads.

Apple’s review process couldn’t detect the malware and green-lighted it to run on all macOS versions, even Big Sur that is currently in beta.

“As far as I know, this is a first: malicious code gaining Apple’s notarization ‘stamp of approval’,” Wardle wrote in the blog post.

Since it was reported, Apple says it has patched and revoked the notarized payloads. Soon after that, however, the same group of attackers somehow released a new, notarized package — which Apple confirmed has been banned as well.

“Malicious software constantly changes, and Apple’s notarization system helps us keep malware off the Mac and allows us to respond quickly when it’s discovered,” Apple commented in a statement to Digital Trends. “Upon learning of this adware, we revoked the identified variant, disabled the developer account, and revoked the associated certificates. We thank the researchers for their assistance in keeping our users safe.”

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Google is testing an AI-first homepage, and the Search button is reportedly taking a back seat
A quietly spotted redesign shows Google testing life without its own Search button.
Google Chrome with Gemini

For years, the Search button has been an integral part of the Google Search experience. However, right now, typing "google.com" into a browser is reportedly bringing up a new simplified layout that doesn’t include the Search button anymore (for a select group of signed-out users). 

It appears that the search giant is testing a new, AI-first layout with three dedicated buttons, which are new for traditional Google Search users, but familiar for those who use the Gemini chatbot on a regular basis.  

Read more
The FCC wants to ban some drones it already approved. Yeah, this is getting complicated.
FCC considers expanding drone restrictions to previously approved DJI models
dji drone

The US Federal Communications Commission is considering a move that could make things pretty awkward for drone buyers. The agency wants to expand its existing restrictions to cover certain drones with features such as LiDAR sensing, thermal imaging, and aerosol-dispersing systems. The weird part? Some of these drones were already approved for sale in the US.

In a report by DJI's own blog, this new development puts several DJI models in the spotlight, including the Air 3S, Avata 360, and Mini 5 Pro. Under the proposal, these drones could potentially be pulled from the US market, even though the FCC had previously cleared them. And no, if you already own one, the government isn't coming to take it away.

Read more
Hoy combines AirDrop, Loom, and voice messages in the Mac menu bar
The pre-release app lets Mac users send files, voice notes, and screen recordings without bouncing between separate tools
Person, Text, Electronics

Hoy wants sending something from your Mac to feel as casual as dropping a file onto someone’s desk. Instead of opening another app, you drag it onto that person’s face sitting in the menu bar.

https://twitter.com/heyiamdk/status/2082151995687748064

Read more