Apple fixes macOS security flaw behind Gatekeeper bypass

Discussion in 'all things Mac' started by guest, Dec 23, 2021.

  1. guest

    guest Guest

    CVE-2021-30853 allowed attackers to bypass: Gatekeeper, Notarization, Quarantine
    December 23, 2021

    Objective-See (Patrick Wardle): Where's the Interpreter!? (CVE-2021-30853)
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Wow, seems to be quite a complex exploit. But seems to be strictly a Gatekeeper bypass, in practice this malware would also need to bypass XProtect, but from what I've read this is not that hard.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Nothing ground breaking and it has already been patched, but it's yet another Gatekeeper bypass. Because of this macOS bug, Gatekeeper wouldn't alert about possible malware.

    https://www.theregister.com/2022/12/20/macos_gatekeeper_flaw_microsoft/
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.