🟠 High | Source: The Register — Security
Security researchers have demonstrated a technique allowing malicious actors to swap legitimate macOS applications with trojanised versions after download, bypassing Gatekeeper — Apple’s primary defence against unauthorised software. The attack exploits weaknesses in how Gatekeeper validates apps post-download rather than at execution time. Apple has reportedly declined to address the issue, leaving users of affected software exposed.
Security Architect’s Take: Organisations deploying macOS endpoints should enforce application allowlisting via MDM solutions such as Jamf or Microsoft Intune, and consider supplementing Gatekeeper with third-party endpoint detection tools that monitor file integrity at execution. Audit your software distribution pipelines to ensure downloads are verified via cryptographic hashes independently of Gatekeeper.
Original advisory: Researchers replace downloaded macOS apps with evil twins, Apple shrugs