Categories: Tech NewsTechCrunch+

Apple fixes bug that let malicious apps skirt macOS’ security protections

Microsoft says a vulnerability it discovered in a core macOS security feature, Gatekeeper, could have allowed attackers to compromise vulnerable Macs with malware.

The flaw, tracked as CVE-2022-42821, was first uncovered by Microsoft principal security researcher Jonathan Bar Or, and dubbed the “Achilles” vulnerability. Bar Or said the bug could allow malware to skirt Gatekeeper’s protections on macOS.

First introduced in 2012, Gatekeeper is a security feature designed to allow only trusted software to run on macOS. The feature automatically verifies that all apps downloaded from the internet are from identified developers who have been “notarized” by Apple, and whose apps are known to be free of malicious content.

Microsoft’s Bar Or explained in a blog post that macOS adds a “quarantine” attribute to apps and files that have been downloaded from a web browser and instructs Gatekeeper to check the file before it can be opened. But the Achilles vulnerability exploits a file permissions model called Access Control Lists (ACLs) to add extremely restrictive permissions to a downloaded file, which prevents web browsers from  properly setting the quarantine attribute.

In exploiting the bug, a user could be tricked into downloading and opening a malicious file on macOS without triggering Gatekeeper’s security protections.

Microsoft reported the Achilles flaw in July, but Apple didn’t acknowledge the vulnerability was fixed until last week.

Bar Or said that Lockdown Mode, an opt-in Apple feature introduced earlier this year to help high-risk users block some of the more sophisticated cyberattacks, would not defend against the Achilles vulnerability, since Lockdown Mode is aimed at stopping silent and remotely triggered “zero-click” attacks that require no user interaction. “End-users should apply the fix regardless of their Lockdown Mode status,” said Bar Or.

Achilles is just one of many Gatekeeper bypasses that have been uncovered in recent years. In April 2021, Apple fixed a zero-day vulnerability in macOS that enabled the threat actors behind the notorious Shlayer malware to bypass Apple’s Gatekeeper and notarization security checks.

Apple fixes bug that let malicious apps skirt macOS’ security protections by Carly Page originally published on TechCrunch

Recent Posts

Unlocking the Secrets of JSON.stringify(): More Than Meets the Eye

JSON (JavaScript Object Notation) is a lightweight data-interchange format widely used in web development. At…

2 months ago

How to Handle AJAX GET/POST Requests in WordPress

AJAX (Asynchronous JavaScript and XML) is a powerful technique used in modern web development that…

3 months ago

Page Speed Optimization: Post-Optimization Dos and Don’ts

Introduction After successfully optimizing your website for speed, it's essential to maintain and build upon…

3 months ago

Ultimate Guide to Securing WordPress Folders: Protect Your Site from Unauthorized Access

Securing your WordPress folders is crucial to safeguarding your website from unauthorized access and potential…

4 months ago

HTML CSS PHP File Upload With Circle Progress Bar

Creating a file upload feature with a circular progress bar involves multiple steps. You'll need…

5 months ago

Using WP Rocket with AWS CloudFront CDN

Integrating WP Rocket with AWS CloudFront CDN helps to optimize and deliver your website content…

5 months ago