
Summary created by Smart Answers AI
In summary:
- Security researchers discovered a macOS vulnerability that allows silent replacement of trusted app executables with malicious versions, though Apple doesn’t consider it a security issue.
- Macworld reports the exploit requires significant attacker access or extensive social engineering, making practical attacks extremely difficult to execute.
- The findings reinforce Mac security best practices: use the App Store, buy directly from developers, and avoid suspicious downloads from unknown sources.
A report by security developers Talal Haj Bakry and Tommy Mysk explains a new bug found in macOS that sounds scary. In a post titled “Silent Replacement of Trusted macOS App Executables,” the researchers describe a security vulnerability that allows an attacker to “secretly replace trusted apps you already have installed from the web with malicious versions.” However, it requires the attacker to jump through so many hoops it’s almost impossible to see any Mac ever being infected.
In simple terms, the bug allows an attacker to bypass macOS’s ability to protect apps from being tampered with. The attack itself involves deleting the app, then copying an altered version of the app to the Mac that has been archived as a tar file. When the app is unarchived, macOS does not detect that the app is a tampered version. Eventually, the user sees the app, thinking it’s a proper version, launches it, and activates the malware.
However, for an attacker to copy the tar file to the Mac, they need access to the machine to delete the authentic app that’s already installed. The attacker needs to physically access the Mac and be able to log in, or they’d have to perform some involved social engineering to persuade the user to perform the necessary tasks.
Bakry and Mysk said they “accidentally” discovered the bug and reported it to Apple. “Apple concluded that the reported behaviour does not constitute a security issue,” said Bakry and Mysk, who also created a video explaining their findings.
How to protect yourself from malware
The easiest way to protect yourself from malware is to avoid downloading software from unfamiliar download sites. Never open links in emails or texts you receive from unknown and unexpected sources. If you get a message that looks like it is from an entity that you do business with, check the sender’s email address and inspect the URL carefully. If you see a link or button, you can Control-click it, select Copy Link Address, and then paste it into a text editor to see the actual URL to check it there.
Apple has vetted software in the Mac App Store, and it is the safest way to get apps. If you prefer not to patronize the Mac App Store, then buy software directly from the developer and their website. If you insist on using cracked software, you will always risk malware exposure.
Macworld has several guides to help, including a guide on whether or not you need antivirus software, a list of Mac viruses, malware, and trojans, and a comparison of Mac security software.

