A massive macOS bug lets hackers bypass all security checks

Owens noted that the bug allowed him to build a malicious app that mimicked a harmless file which in turn helped bypass macOS' built-in security mechanisms when opened.

Published - April 28, 2021 09:04 am IST

A massive macOS bug lets hackers bypass all security checks.

A massive macOS bug lets hackers bypass all security checks.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

Hackers exploited a massive macOS software bug that allowed them to bypass core Apple security checks and leave Mac users at grave risk, according to security researchers Cedric Owens and Patrick Wardle.

Owens noted that the bug allowed him to build a malicious app that mimicked a harmless file which in turn helped bypass macOS' built-in security mechanisms when opened.

"It's the most dangerous macOS payload I have encountered on recent versions of macOS because it completely bypasses Gatekeeper and the user does not even get any pop-ups or warnings," Owens told The Hindu .

Owens explained that a user just has to do download the ‘.dmg’ or ‘.zip’ file that contains the payload. Once double clicked, the payload silently detonated without warning the victim.

He had reported the bug to Apple, and the company has patched the bug in macOS 11.3. Owens urged all users to update to BigSur 11.3 to avoid any security risk.

Also Read : Apple’s security check fails second time in six weeks

Patrick Wardle, a Mac security researcher, explained in a blog post how and why the bug works. He said that due to a subtle logic bug in Apple's policy engine, it was possible to create a malicious app without being notarised. And that Apple's app review process allowed the app to launch without any prompts or alerts.

Wardle noted that the harmless PDF document, without notarisation, was able to launch the calculator app and do other things.

He added that the bug could have been introduced with macOS 10.15's new notarisation logic, meaning Apple's idea to secure macOS backfired.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.