Researchers replace downloaded macOS apps with evil twins, Apple shrugs

← Back to the feed

Researchers replace downloaded macOS apps with evil twins, Apple shrugs

The Register · 3 hours ago

Researchers Talal Haj Bakry and Tommy Mysk say they found a flaw in macOS Gatekeeper that can allow a previously downloaded and opened app to be replaced with a malicious “evil twin” without triggering a new security warning. The issue matters because users may continue to trust familiar applications while attackers use the altered version to display convincing prompts or run harmful code.

The attack is not zero-click: an attacker must already be able to run code with the user’s privileges, for example through a malicious app, script or supply-chain compromise. It affects apps downloaded from the web, including examples such as Brave, Slack, Signal and Visual Studio Code, but not Mac App Store apps, whose root ownership prevents replacement by ordinary user processes. The researchers demonstrated archiving a validated app with tar, replacing it, and reopening it without reauthorisation; they suspect cached trust information may cause macOS to accept the modified bundle.

  • Gatekeeper may trust altered web-downloaded apps after their first launch.
  • Attackers need existing user-level code execution.
  • Mac App Store apps are not affected.

Business Markets Research Science Software Technology

Read the full article at the source →