Apple Adds ClickFix Attack Warnings in New macOS Tahoe Security Feature
ID: 9c051100-0350-50f5-9393-93f7896562e6
STIX ID: report--9c051100-0350-50f5-9393-93f7896562e6
Feed Name: GBHackers
Apple quietly added a Terminal paste-interception feature in macOS Tahoe 26.4 to mitigate 'ClickFix' social-engineering attacks that coerce users into pasting and executing malicious commands. ClickFix campaigns typically present fake CAPTCHAs, installers, or chat prompts instructing users to paste encoded scripts or sudo commands that download infostealers like MacSync to steal Keychain items, browser cookies, credentials, and crypto wallet data; the new protection blocks the paste and shows a prominent “Possible malware, Paste blocked” dialog with options to abort or proceed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
