macOS malware has been on the rise in recent years . That's why Apple has added several layers of protection that make it much harder for malware to install and run on a Mac . But a vulnerability in the operating system, which was publicly disclosed and promptly patched by Apple, has already been used to bypass those layers of security.

Security researcher Cedric Owens discovered the vulnerability in mid-March while examining macOS defenses. Apple's Gatekeeper mechanism requires developers to register with Apple and pay a fee (a subscription fee) so that their software can run on Macs. The company's software notarization process requires all applications to undergo an automated review process. The flaw Owens found was not found in those systems, but rather in macOS itself. According to his findings, attackers could have crafted the malwarein such a way that it could trick Apple's operating system into allowing the malware to run even if it failed all security checks.
See also: Serious bug fixed in MacOS Big Sur installation
“With all the security improvements Apple has made in recent years, I was quite surprised that this simple technique worked,” Owens says, “So I immediately reported it to Apple, given that real attackers could use this technique to bypass Gatekeeper. There are many ways to exploit this bug.”
Apple incorrectly that all apps always have certain features. Owens discovered that if he created an app that was like a script (i.e. code that tells another program what to do instead of doing it himself) and didn’t include a standard application metadata file called “info.plist,” he could run the app on any Mac. macOS wouldn’t ask the basic question: “This app was downloaded from the Internet. Are you sure you want to open it?”
See also: Sudo bug: Also affects devices using macOS
Owens reported the bug to Apple and also shared his findings with macOS security researcher Patrick Wardle, who analyzed the security issue in more detail.

“The operating system correctly says, ‘Wait a minute, this is from the Internet, I’ll do all my checks,’” Wardle says. First, macOS checks to see if the notarization process has been done, which in this case it hasn’t. However, it then checks to see if the software is an application package. When it sees that there’s no “info.plist” file, macOS incorrectly concludes that the software isn’t an application, ignores any other evidence to the contrary, and lets it run without any attention from the user. “It just says, ‘Okay, cool,’ and runs whatever,” Wardle says. “It’s crazy!”
After better understanding how the bug worked and how it could allow malware to run on macOS, Wardle contacted Jamf, a software provider for system administrators who deal with Apple devices, to see if the company's antivirus product had flagged any malware. In fact, Jamf had flagged a version of the Shlayer adware that exploited the bug.
See also: REvil gang demands ransom from Apple to stop leaking product designs
“This completely undermines many basic, fundamental elements of macOS“.
Yesterday, Apple released a security update to fix the vulnerability in macOS Big Sur 11.3 and block potential malware attacks.
Users now receive a notification that malicious applications “cannot be opened because the developer cannot be identified” and are advised to remove the disk image because it may contain malware.
Source: Times News Express
