Security researchers have demonstrated a significant flaw in macOS security by successfully replacing downloaded applications with 'evil twin' versions. Despite the presence of Apple's Gatekeeper, which is designed to ensure that only trusted software runs on the system, the mechanism failed to prevent the execution of modified, malicious code in certain scenarios.
The Gatekeeper Vulnerability
Gatekeeper’s primary function is to verify the developer's signature and check for known malware before an app is opened for the first time. However, the researchers found that for specific software packages, the system does not adequately re-verify the integrity of the application after it has been initially cleared, allowing a malicious actor to swap legitimate files with compromised ones.
Apple's Response
Despite the demonstration of this vulnerability, the researchers noted that Apple has remained largely dismissive of the findings. The tech giant has not yet committed to a fundamental change in how Gatekeeper handles these specific edge cases, leading to concerns about the long-term effectiveness of the security feature against sophisticated file-replacement attacks.




