Researchers have discovered OSX/Linker malware exploiting an unpatched macOS flaw that would allow a malicious binary to bypass the Gatekeeper scanning process
Researchers find new OSX/Linker malware abusing still-unpatched macOS Gatekeeper bypass. — Mac malware developers have jumped …
Context & Ripple Effects
OSX/Linker is the latest entry in a long-running pattern around macOS Gatekeeper. Back in January 2016, a researcher showed Apple had merely blacklisted programs abusing a Gatekeeper vulnerability rather than fixing the underlying cause — leaving the door open for new malware to walk through it.
The playbook has repeated since: in 2017 Check Point detailed Dok, OS X malware that slipped past Gatekeeper using a signed Apple developer certificate. OSX/Linker's abuse of an unpatched flaw shows the same defense-in-depth gap persisting years later.
First-order effects
- Mac users running current-but-unpatched macOS builds are exposed to unsigned binaries that skip Gatekeeper scanning entirely, since the bypass requires no user approval.
- Apple faces pressure to patch the underlying flaw rather than repeat its 2016 approach of blacklisting individual malicious binaries one at a time.
Second-order effects
- Enterprise Mac fleets become a soft target relative to Windows estates with more mature endpoint controls, pushing IT buyers toward third-party security tooling on macOS.
- Each published bypass lowers the barrier for copycat malware authors, who can reuse the technique until Apple ships a fix — exactly what followed the Dok disclosure.
Third-order effects
- Gatekeeper's notarization-and-signing model keeps proving to be a single point of failure: the same class of flaw resurfaced in a notarization bypass that went unpatched for months until Big Sur 11.3, and again in a Gatekeeper bypass reported by Microsoft and fixed in late 2022.
- If bypasses keep recurring at this cadence, macOS security will consolidate around layered defenses beyond Gatekeeper itself — third-party endpoint protection and faster patch cycles — rather than trust in any single Apple gate.
The trend: macOS malware is converging on Gatekeeper bypasses as the primary attack vector, and each disclosed flaw shows Apple's signing-based gatekeeping is a recurring target rather than a solved problem.