HomeSecurityMicrosoft: macOS vulnerability allowed Gatekeeper bypass

Microsoft: macOS vulnerability allowed Gatekeeper bypass

Apple has fixed a vulnerability that would have allowed hackers to install malware on unsuspecting people's through apps that bypass Gatekeeper restrictions against untrusted apps.

macOS vulnerability

The security flaw, identified as CVE-2022-42821, was discovered and reported by Microsoft's principal security researcher, Jonathan Bar Or.

Apple addressed the bug in macOS 13 (Ventura), macOS 12.6.2 (Monterey), and macOS 1.7.2 (Big Sur) a week ago, on December 13, 2022.

Gatekeeper bypass

Gatekeeper in macOS is a security feature that scans apps you download from the internet for compatibility and security. If an app isn't approved by Apple, Gatekeeper issues a warning before allowing you to open it.

See also: H-Hotels: Play ransomware responsible for cyberattack

This is achieved by checking an extended attribute called com.apple.quarantine, which is assigned by browsers to all downloaded files (Mark of the Web works similarly on Windows).

The macOS vulnerability discovered by the Microsoft researcher allows specially crafted payloads to abuse an issue to set restrictive Access Control List (ACL) permissions that prevent web browsers and Internet downloaders from setting the com.apple.quarantine attribute for download payloads archived as ZIP files.

As a result, the malicious application contained in the archived malicious payload is launched on the target system instead of being blocked by Gatekeeper. Thus, cybercriminals can download and deploy malware on macOS devices.

Gatekeeper bypasses like this could be exploited as an initial access vector by malware and other threats and could help increase the success rate of malicious campaigns and attacks on macOS.

On Monday, Microsoft said that the Lockdown Mode introduced in Apple's macOS Ventura is an optional security measure for users at high risk of becoming targets of sophisticated cyberattacks. However, it is designed to protect against zero-click remote code execution exploits. It does not protect against the CVE-2022-42821 vulnerability.

See also: T-Mobile: New SIM Protection feature released!

"End users should apply the fix regardless of Lockdown Mode status," the Microsoft team added.

macOS and malware

Over the years, numerous Gatekeeper bypasses have been found – with many of them being used by attackers to bypass mechanisms security like Gatekeeper, File Quarantine, and System Integrity Protection (SIP) on Macs that are fully up-to-date.

Gatekeeper
Microsoft: macOS vulnerability allowed Gatekeeper bypass

For example, Bar Or found a security flaw known as Shrootless in 2021. This allows threat actors to bypass System Integrity Protection – SIP to do whatever they want on a compromised Mac. They could even install rootkits on the device.

The researcher has also discovered powerdir , a flaw that allows attackers to bypass Transparency, Consent, and Control (TCC) technology to access protected user data .

Additionally, he published exploit code for a macOS vulnerability (CVE-2022-26706). Attackers could use it to bypass sandbox restrictions and execute code on the system.

See also: Malicious PyPI package “SentinelOne” steals data from developers

Finally, Apple patched a macOS vulnerability in April 2021 that allowed malicious actors behind the notorious Shlayer malware to bypass Apple's File Quarantine, Gatekeeper, and Notarization security measures and download additional malware to infected Macs.

Overall, these macOS security vulnerabilities demonstrate how important it is for Mac users to be vigilant when it comes to online. Apple releases patches for security issues, so make sure you always keep your operating system up to date with all the latest updates – this will go a long way in keeping you safe from potential threats and attacks related to these security vulnerabilities.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS