< Back to all clusters
[TECHNOLOGY] · United States, Germany · 2 sources

Apple macOS Gatekeeper flaw lets verified apps be silently replaced

A newly disclosed vulnerability in macOS’s Gatekeeper allows a previously verified application bundle to be silently swapped with a malicious version after the initial check, without triggering a new security warning. The issue primarily affects apps that are not distributed through the Mac App Store and can be exploited by an attacker who already has system access, enabling silent deployment of malware.

In parallel, Apple introduced an additional security mechanism in macOS 27 “Golden Gate” that expands sandbox protections to specific Application‑Support folders used by browsers, cryptocurrency wallets and other apps. The protection is enforced through the XProtect framework, preventing unauthorized terminal access to those directories and allowing Apple to add new protected locations dynamically.

Both developments highlight Apple’s ongoing efforts to strengthen macOS defenses while exposing a critical bypass that could undermine the platform’s app‑verification model.

Entities: Apple Inc. · Gatekeeper · Wojciech Reguła · XProtect · macOS