logo

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

ID: 6b3c3909-7bb5-5383-8bc8-3389da5e2022

STIX ID: report--6b3c3909-7bb5-5383-8bc8-3389da5e2022

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

Security researchers Talal Haj Bakry and Tommy Mysk disclosed a Gatekeeper bypass in macOS that permits replacing the main executable of apps downloaded from the internet (but not App Store apps) after they have been run once. The technique archives and restores the app bundle (for example with tar), causing macOS to treat the bundle as locally built and skip revalidation, enabling malicious replicas to be executed without elevated privileges; Apple was notified and closed the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.