• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft details gatekeeper bypass vulnerability in apple macos systems

Microsoft Details Gatekeeper Bypass Vulnerability in Apple macOS Systems

You are here: Home / General Cyber Security News / Microsoft Details Gatekeeper Bypass Vulnerability in Apple macOS Systems
December 20, 2022

Microsoft has disclosed aspects of a now-patched security flaw in Apple macOS that could be exploited by an attacker to get around security protections imposed to protect against the execution of malicious programs.

The shortcoming, dubbed Achilles (CVE-2022-42821, CVSS score: 5.5), was addressed by the iPhone maker in macOS Ventura 13, Monterey 12.6.2, and Big Sur 11.7.2, describing it as a logic issue that could be weaponized by an app to circumvent Gatekeeper checks.

“Gatekeeper bypasses these kinds of as this could be leveraged as a vector for original entry by malware and other threats and could assist increase the good results rate of destructive campaigns and attacks on macOS,” Jonathan Bar Or of the Microsoft 365 Defender Investigation Staff mentioned.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


CyberSecurity

Gatekeeper is a security mechanism created to assure that only trustworthy applications run on the functioning process. This is enforced by suggests of an prolonged attribute called “com.apple.quarantine” that is assigned to documents downloaded from the internet. It is analogous to the Mark of the Web (MotW) flag in Windows.

Consequently when an unsuspecting consumer downloads a probably unsafe app that impersonates a piece of legit computer software, the Gatekeeper element helps prevent the apps from currently being operate as it really is not validly signed and notarized by Apple.

Even in situations where an app is accredited by Apple, people are shown a prompt when it can be introduced for the very first time to find their specific consent.

Presented the critical function played by Gatekeeper in macOS, it truly is challenging not to picture the effects of sidestepping the security barrier, which could successfully allow danger actors to deploy malware on the machines.

The Achilles vulnerability discovered by Microsoft exploits a permission model termed Accessibility Handle Lists (ACLs) to insert exceptionally restrictive permissions to a downloaded file (i.e., “every person deny compose,writeattr,writeextattr,writesecurity,chown”), thus blocking Safari from placing the quarantine prolonged attribute.

In a hypothetical attack state of affairs, an adversary could embrace the approach to craft a rogue app and host it on a server, which could then be shipped to a achievable target by way of social engineering, destructive advertisements, or a watering hole.

The technique also circumvents Apple’s freshly released Lockdown Manner in macOS Ventura – an decide-in restrictive location to counter zero-simply click exploits – necessitating that users utilize the most up-to-date updates to mitigate threats.

“Faux applications continue to be a person of the top rated entry vectors on macOS, indicating Gatekeeper bypass methods are an interesting and even a needed capacity for adversaries to leverage in attacks,” Bar Or reported.

Discovered this post intriguing? Follow us on Twitter  and LinkedIn to read much more special content we article.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «researchers discover malicious pypi package posing as sentinelone sdk to Researchers Discover Malicious PyPI Package Posing as SentinelOne SDK to Steal Data
Next Post: FTC Fines Fortnite Maker Epic Games $275 Million for Violating Children’s Privacy Law ftc fines fortnite maker epic games $275 million for violating»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.