Blog | G5 Cyber Security

How malware developers could bypass Macs Gatekeeper without really trying

Security researcher who discovered the original vulnerability says he found an obvious work-around. Patrick Wardle said the security fix consisted of blacklisting a small number of known files he privately reported to Apple that could be repackaged to install malicious software on Macs. Wardle was able to revive his attack with little effort by finding a new Apple trusted file that hadn’t been blocked by the Apple update. The hack works by renaming the Apple-trusted file but otherwise making no other changes to it. Apple says the new files Wardle reported have been blocked using XProtect.”]

Source: https://arstechnica.com/information-technology/2016/01/how-malware-developers-could-bypass-macs-gatekeeper-without-really-trying/

Exit mobile version