Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Washington Family Sues Nara Organics and Target After Their Infant Was Hospitalized with Botulism from Recalled Organic Formula

    How to Watch MLB Today: Schedule, TV, Streaming for Dodgers-Mets, Mariners-Rangers, Padres-Marlins

    Trump faces AI backlash from unions and data-center critics: Analysis

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest VKontakte
    Sg Latest NewsSg Latest News
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Health
    • Sports
    Sg Latest NewsSg Latest News
    Home»Technology»Mac apps could conceivably be replaced by malware
    Technology

    Mac apps could conceivably be replaced by malware

    AdminBy AdminNo Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    It takes a very specific series of steps and even then it cannot affect every Mac app, but researchers have found a way to bypass Apple’s macOS security and run malware.

    If they don’t already come installed on the Mac, macOS apps are either downloaded from the Mac App Store, or from developers’ websites. Whichever it is, macOS has security measures to prevent bad actors running malware on Macs, but researchers say they have found a way around this.

    Researchers Talal Haj Bakry and Tommy Mysk also say in a blog post that they reported their findings, but Apple is unconcerned. Apple has good reason, but it is still a potential weakness that the researchers believe could be readily fixed.

    “A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges,” write the researchers. “As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched.”

    This is all true, but it isn’t as big a threat as it sounds. For one thing, no apps downloaded from the Mac App Store are vulnerable to it. Only ones from websites could be, and even then the researchers say this has to happen:

    • The app is downloaded and installed
    • It is launched at least once
    • An attacker has already remote or physical access to the Mac

    In this situation, an attacker could then archive the app using .tar and delete the original. Then they extracts the archive.

    If they do that, the unarchived app will launch and will not trip macOS’s Gatekeeper security systems. It remains a trusted app and can run unchecked. In a demo of the process, the researchers modified an app which then prompted the user for permission to access files and folders.

    Since everything about that prompt is a macOS dialog triggered by an app the user trusts, they are more likely to enter their password. The demo of this ends with the app, having been given these permissions, restores the original code.

    So in the right circumstances, an app could be swapped out for a malicious one, which then hides itself after executing whatever malware it intended.

    Only, this not only requires someone having access to archive off the app, it needs that bad actor to have access to that Mac. The researchers say that a requirement is that the “attacker already has code execution as the current user, for example through a malicious app or downloaded script.”

    Consequently, if the bad actor already has remote or physical access to the Mac, they can in theory do this. That means the user has to have been vulnerable to a previous attack in order for this one to be possible.

    According to the researchers, Apple had many reasons for concluding that this is not a security issue. One is that it comes down to convincing the user to take multiple steps, which Apple reportedly considers to be “a matter of social engineering rather than a bypass” of security mechanisms.

    Apple is right, but the researchers have a point, too.

    How it works and what can be changed

    This exploit works because apps have to be signed, they have to be notarized. But it’s the whole app that Apple confirms belongs to a legitimate developer, it is not every single element in that app.

    So when the archived and unarchived app is launched, it is still considered the same app even though a key part of it has been altered.

    The researchers suggest that the unarchived app should be checked again as if it is a new installation. They note that macOS requires the app to ask for permissions again, so it has detected that there has been some change.

    That seems reasonable, and it doesn’t sound as if it would inconvenience the user.

    How to protect yourself against this vulnerability

    You could solely use apps you’ve got from the Mac App Store. These work slightly differently because such apps are installed for all users of a Mac, where ones from the web are usually owned by the current owner who downloaded them.

    This means that the way permissions and the Gatekeeper checking of notarized apps is slightly different. The upshot is that this workaround simply can’t be used on Mac App Store apps.

    That’s not especially practical, given how most Mac apps are not available on the store. So you need to prevent bad actors getting access to your Mac.

    Read the AppleInsider guide to protecting your Mac from most forms of attack.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin
    • Website

    Related Posts

    Roku raises streaming stick prices by up to 60 percent

    ChatGPT now has a space for sharing medical records. Should you?

    How to Choose a Speech Recognition Engine for Your App – Research Snipers

    Turn off ads across your family’s devices with one $11 purchase

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Most Impressive Team Streaks Of The 21st Century: Where Does 2024-26 Spain Rank?

    NBC’s ‘Stumble’ is a mockumentary about a cheer team with plenty of tumbling runs and heart

    Xiaomi shares post worst week in 3½ years as accidents stoke EV safety concerns

    Judge reverses Trump administration’s cuts of billions of dollars to Harvard University

    Top Reviews
    9.1

    Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

    By Admin
    8.9

    Comparison of Mobile Phone Providers: 4G Connectivity & Speed

    By Admin
    8.9

    Which LED Lights for Nail Salon Safe? Comparison of Major Brands

    By Admin
    Sg Latest News
    Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
    • Get In Touch
    © 2026 SglatestNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.