Gatekeeper Bypass: Uncovering Weaknesses in a macOS Security Mechanism
ID: 876e3f37-dc0a-53d2-8fa2-b6b501718a76
STIX ID: report--876e3f37-dc0a-53d2-8fa2-b6b501718a76
Feed Name: Palo Alto Networks Unit 42
Threat Score
Unit 42 found that several third-party macOS utilities (archive apps, virtualization tools) and some native command-line tools do not preserve the com.apple.quarantine extended attribute, allowing files to bypass Gatekeeper checks. The report documents affected products and formats, demonstrates the bypasses, cites past malware using similar behaviors, and urges developers to enforce quarantine propagation while recommending layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
