Mac exploit dodges Apple’s anti-malware app check
If you’ve used a Mac running OS X Mountain Lion or later, you’re well-acquainted with Gatekeeper: it’s the security measure that prevents unsigned apps from running unless you want them to. Unfortunately, it turns out that this first line of defense isn’t quite as secure as it’s supposed to be. Synack security researcher Patrick Wardle has discovered a flaw that lets malware get around Gatekeeper and do what it wants with your system. The trick ‘hijacks’ a signed app to pretend that it’s legit, and uses clever file packaging to launch hostile code once OS X declares the host app safe. Wardle only used one app in a proof of concept demonstration, but other apps should work. You could even use malicious plugins (say, Photoshop add-ons) to bypass Gatekeeper.
Needless to say, this is a potentially nasty flaw. If attackers can convince you to download and install an authentic-looking app, they’ll have a field day. The good news? Wardle took care to notify Apple before disclosing the exploit, and the company says that it’s already working on a patch. It’s not clear when this will arrive, so you’ll want to stay on your toes until then — grab apps only from those sources you can trust.
[Image credit: Getty Images/OJO Images RF]
Via: Ars Technica
Source: Virus Bulletin