Apple Gatekeeper Bug Suggests Sleepy Approach To OS Security
ID: 576b423c-20e9-5a05-9af5-010be1cf86de
STIX ID: report--576b423c-20e9-5a05-9af5-010be1cf86de
Feed Name: Security Ledger
A researcher disclosed a Gatekeeper bypass in OS X El Capitan where Gatekeeper validates only the signed application within an archive (ZIP/DMG) and not other bundled components; attackers can include unsigned malicious libraries or plugins in the archive that are later executed when the signed app runs. The flaw enables execution of malicious code via social engineering (download from untrusted sites) and was reported to Apple, with suggested fixes to enforce signature checks on add-on components and trusted load paths. No public evidence of active exploitation was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
