• Latest
Mac Gatekeeper bypass vulnerability fixed by Apple

Mac Gatekeeper bypass vulnerability fixed by Apple

December 20, 2022
iPhone 14 Review: Repackaging 101!

iPhone 14 Review: Repackaging 101!

March 25, 2023

Recapping All the Best Drama – The TouchArcade Show #552 – TouchArcade

March 25, 2023
How ONE Company Keeps The Internet Running – AWS Explained

How ONE Company Keeps The Internet Running – AWS Explained

March 25, 2023
Top 5 Data Streaming Trends for 2023

Top 5 Data Streaming Trends for 2023

March 25, 2023
🔥 UNLIMITED AFK XP🔥  Fortnite Creative Map Glitch – Chapter 4 Season 2 *NOT PATCHED*

🔥 UNLIMITED AFK XP🔥 Fortnite Creative Map Glitch – Chapter 4 Season 2 *NOT PATCHED*

March 25, 2023
10 Things to Know When Using SHACL With GraphDB

10 Things to Know When Using SHACL With GraphDB

March 25, 2023
OPPO Find X6 Pro Review – The Photography KING!

OPPO Find X6 Pro Review – The Photography KING!

March 25, 2023
LEGO 2K Drive Will Include Real Money Transactions

LEGO 2K Drive Will Include Real Money Transactions

March 25, 2023
Carl Pei imitating youtubers | MKBHD | Mrwhosetheboss | JerryRigEverything | Technical Guruji

Carl Pei imitating youtubers | MKBHD | Mrwhosetheboss | JerryRigEverything | Technical Guruji

March 25, 2023
When Does The 3DS And Wii U eShop Close? Nintendo eShop Closure Guide

When Does The 3DS And Wii U eShop Close? Nintendo eShop Closure Guide

March 25, 2023
Samsung may launch a Tri-Fold device this year, the S23 FE isn’t happening

Samsung may launch a Tri-Fold device this year, the S23 FE isn’t happening

March 25, 2023
Sonic Origins Plus Will Apparently Fix Some Pesky Bugs

Sonic Origins Plus Will Apparently Fix Some Pesky Bugs

March 25, 2023
Advertise with us
Saturday, March 25, 2023
Bookmarks
  • Login
  • Register
GetUpdated
  • Game Updates
  • Mobile Gaming
  • Playstation News
  • Xbox News
  • Switch News
  • MMORPG
  • Game News
  • IGN
  • Retro Gaming
  • Tech News
  • Apple Updates
  • Jailbreak News
  • Mobile News
  • Software Development
  • Photography
  • Contact
No Result
View All Result
GetUpdated
No Result
View All Result
GetUpdated
No Result
View All Result
ADVERTISEMENT

Mac Gatekeeper bypass vulnerability fixed by Apple

December 20, 2022
in Apple News
Reading Time:3 mins read
0 0
0
Share on FacebookShare on WhatsAppShare on Twitter


A serious Mac Gatekeeper bypass vulnerability has been fixed by Apple, after it was discovered and reported by security researchers at Microsoft.

The flaw allowed malware to bypass Gatekeeper checks. Notably, the vulnerability even affected Macs running in ultra-safe Lockdown Mode …

Gatekeeper

Gatekeeper is a security feature built into macOS. When you attempt to run a new Mac app for the first time, Gatekeeper checks to see whether it has been notarized by Apple as coming from a recognized developer.

There are three user-selectable Gatekeeper settings:

  • Allow only those apps downloaded from the Mac App Store
  • Also allow those signed by certified Apple developers
  • Allow all apps

(Current and recent versions of macOS hide the third option, ensuring it cannot be selected inadvertently.)

When a new app is downloaded from the web, an attribute called com.apple.quarantine is assigned to the file, which is the signal for Gatekeeper to check it on opening.

Mac Gatekeeper bypass vulnerability

Bleeping Computer reports that a macOS flaw allowed an attacker to prevent the com.apple.quarantine attribute being assigned to the file, meaning that it wouldn’t trigger the Gatekeeper check when opened.

The Achilles flaw allows specially-crafted payloads to abuse a logic issue to set restrictive Access Control List (ACL) permissions that block web browsers and Internet downloaders from setting the com.apple.quarantine attribute for downloaded the payload archived as ZIP files.

As a result, the malicious app contained within the archived malicious payload launches on the target’s system instead of getting blocked by Gatekeeper, allowing attackers to download and deploy malware.

Notably, Lockdown Mode did not protect against the vulnerability.

Microsoft said on Monday that “Apple’s Lockdown Mode, introduced in macOS Ventura as an optional protection feature for high-risk users that might be personally targeted by a sophisticated cyberattack, is aimed to stop zero-click remote code execution exploits, and therefore does not defend against Achilles.”

As ever, it’s recommended to keep your Mac and other Apple devices fully updated. If you don’t want to update to Ventura, Apple offers the option to update to the latest (and most secure) version of earlier macOSes.

Apple is currently testing a new Rapid Security Response feature for both Mac and iOS devices, which will allow it to quickly patch security vulnerabilities like this without the need for a full OS update.

Photo: Ján Vlačuha/Unsplash

FTC: We use income earning auto affiliate links. More.


Check out 9to5Mac on YouTube for more Apple news:



Source link

ShareSendTweet
Previous Post

Top 10 layouts from the 2022 AUDL season

Next Post

Stardew Valley creator has “big, ambitious vision” for next game, Haunted Chocolatier

Related Posts

WhatsApp working on new short video messages

March 25, 2023
0
0
WhatsApp rolling out voice support for posting status updates
Apple News

The popular messaging platform WhatsApp currently offers multiple ways to communicate beyond text, such as pictures, videos, and even calls....

Read more

PSA: Don’t steal AirPods, they’re basically AirTags

March 25, 2023
0
0
PSA: Don’t steal AirPods, they’re basically AirTags
Apple News

Apple’s AirTag has become known for helping people find their lost items, but there are other Apple products that also...

Read more
Next Post
Stardew Valley creator has “big, ambitious vision” for next game, Haunted Chocolatier

Stardew Valley creator has "big, ambitious vision" for next game, Haunted Chocolatier

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

© 2021 GetUpdated – MW.

  • About
  • Advertise
  • Privacy & Policy
  • Terms & Conditions
  • Contact

No Result
View All Result
  • Game Updates
  • Mobile Gaming
  • Playstation News
  • Xbox News
  • Switch News
  • MMORPG
  • Game News
  • IGN
  • Retro Gaming
  • Tech News
  • Apple Updates
  • Jailbreak News
  • Mobile News
  • Software Development
  • Photography
  • Contact

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?