Saturday, July 25, 2026

Experts claim to have found more weaknesses in Apple’s Gatekeeper tool — but it doesn’t seem too bothered


  • Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware
  • Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify
  • Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering

A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.

Gatekeeper’s modus operandi is rather simple – when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it – it won’t allow it to run on the machine.

Related Articles

Latest Articles