Researchers say macOS can keep trusting some apps downloaded from the web even after their main executable file is swapped for a malicious one. The issue affects non-App-Store macOS apps that have already been opened once and passed Gatekeeper's first validation; after that, an attacker with user-level code execution can replace the app bundle and macOS may not re-prompt or block it. No CVE or patch is mentioned, and Apple reportedly closed the report without a fix.
Why it matters: Mac users and organizations that rely on Gatekeeper for downloaded apps may not be protected if malware already running as the user can replace a trusted app with an evil twin. Until Apple changes the behavior, defenders should limit user-level code execution, scrutinize command-line install flows, and prefer managed or App Store software where possible.
2026.07.23
100% relevant
This article appears to be the first cited report establishing the specific Gatekeeper trust-bypass behavior for once-run, web-downloaded macOS apps.
← Back to all stories