You are here: Home / Vulnerabilities / Hackers can install malware on macOS through a vulnerability in GatekeeperMacOS, Apple’s operating system, has a feature called Gatekeeper , which allows only trusted applications to run, verifying and ensuring that the software has been signed by the App Store or a registered developer and has been approved a process called “app notarization” that scans software for malicious content. Apple has released an update to macOS operating systems to fix the zero-day vulnerability, which was being actively exploited and allowed all security protections to be bypassed, thus allowing unapproved software to run.

“An unsigned and unannotated script-based proof-of-concept application could trivially and reliably bypass all relevant macOS security mechanisms (file quarantine, gatekeeper and notarization requirements), even on a fully patched macOS M1 system. Armed with such a capability, macOS malware authors could (and are) reverting to their tried-and-true methods for attacking and infecting macOS users.” Patrick Wardle in his article on the vulnerability

Malicious hackers exploited a vulnerability in fully updated versions of macOS that allowed them to take screenshots on infected Macs without first obtaining permission from the victims.

The infections came in the form of malicious projects that the attacker wrote for Xcode, a tool that Apple makes freely available to developers writing applications for macOS or other Apple operating systems. As soon as one of the XCSSET projects has been opened and built, TrendMicro said, the malicious code will run on developers’ Macs. An Xcode project is a repository of all the files, resources and information needed to create an application.

On Monday, researchers at Jamf, a security vendor for Apple business users, said XCSSET exploited a zero-day that had gone unnoticed until recently. The vulnerability lies in the consent and transparency audit framework, which requires explicit user permission before an installed app can gain system permissions to access the hard drive, microphone, camera and other privacy- and security-sensitive resources.