/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher shows that for months macOS had a flaw that would let apps run despite not being notarized by Apple's service; bug is patched in macOS Big Sur 11.3

Old malware, new tricks.  —  Apple has spent years reinforcing macOS with new security features to make it tougher for malware to break in.

TechCrunch Zack Whittaker

Context & Ripple Effects

Apple’s application-trust controls had already been tested by a Gatekeeper weakness Apple addressed by blacklisting offending programs and by OSX/Linker malware that bypassed Gatekeeper scanning. The Big Sur patch matters because it closes another path around the notarization layer rather than a conventional malicious app slipping through it.

First-order effects

  • Macs updated to Big Sur 11.3 no longer accept non-notarized apps through the disclosed flaw, removing that route for malware operators.
  • Apple restores the intended enforcement of its notarization service for affected Big Sur systems.

Second-order effects

  • The recurring focus on bypassing Gatekeeper means Apple must treat trust-check enforcement, not just malware detection, as a patching priority; a later Microsoft-reported Gatekeeper bypass reinforces that pressure.
  • Users and organizations that delay macOS updates retain exposure to a weakness that the platform’s app-trust controls were meant to prevent.

Third-order effects

  • The pattern points to macOS security becoming a continuous maintenance problem: notarization and Gatekeeper provide a trust boundary only when their implementation flaws are rapidly found and patched.
  • Repeated bypasses could shift the practical value of Apple’s app-review signals toward update responsiveness and vulnerability remediation, rather than reliance on any single screening layer.

The trend: macOS is evolving toward layered application trust controls whose effectiveness depends on ongoing fixes for bypasses at the enforcement boundary.

Discussion

  • @cedowens Cedric Owens on x
    Kudos to Apple for quickly fixing the bug I reported to them. Here is my blog that delves into how I weaponized this bug with a payload: https://medium.com/.... Thanks @patrickwardle for helping dive into the vuln as well 🙏🏽 https://twitter.com/...
  • @micahflee Micah on x
    This macOS quarantine/gatekeeper/notarization bypass vuln is wild in its simplicity. I just made this little video of typing out the exploit and executing an unsigned, unnotarized app bundle that can do anything it wants (in macOS 11.2.3) https://objective-see.com/... https://twi…
  • @patrickwardle Patrick Wardle on x
    1⃣ Update to macOS 11.3, like now. 2⃣ Read about, IMHO, the worst macOS bug in recent memory (in terms of its ease of exploitability and potential impact to everyday Mac users). https://twitter.com/...
  • @lapcatsoftware Jeff Johnson on x
    “It appears that this bug was introduced in macOS 10.15 ...thus older versions of macOS do not seem be vulnerable.” Staying on Mojave FTW! LOL  do u even test ur code https://twitter.com/...
  • @jeremy_kirk Jeremy Kirk on x
    @cedowens deserves a round of applause for finding this zero-day. He's the “anonymous researcher” in Apple's advisory, but that is an oversight that Apple is in the process of rectifying. https://support.apple.com/...
  • @patrickwardle Patrick Wardle on x
    CVE-2021-1810 🍎: “a malicious app may bypass Gatekeeper” Researchers collaboratively publish: 1️⃣ Root cause 2️⃣ Patch analysis 3️⃣ Details of in-the-wild exploitation 4️⃣ Scripts for protections/detections 5️⃣ PoC exploit (to test #4) Vendors, do better pls! 😇🙏 https://twitter.c…
  • @edbott Ed Bott on x
    Wait, I was told that Macs are completely immune from this sort of thing. Next you're gonna tell me Santa Claus isn't real. https://twitter.com/...
  • @objective_see Objective-See on x
    In collaboration w/ @JamfSoftware, we uncovered the fact that attackers were *already* exploiting this flaw successfully as an 0day 😱 Shortly, they'll be posting more about their findings & analysis: “Shlayer Malware Abusing Gatekeeper Bypass On Macos”: https://www.jamf.com/... h…
  • @jamfsoftware Jamf on x
    ICYMI: Jamf's cybersecurity experts in-depth research on the malicious Shlayer macOS malware. https://ow.ly/...
  • @stuartjash Stuart Ashenbrenner on x
    After @patrickwardle's writeup on the bug found by @cedowens in macOS, my team over at @JamfSoftware Protect found the bug being (ab)used in the wild 👀 https://www.jamf.com/... @objective_see - https://objective-see.com/... https://medium.com/... https://www.forbes.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: hackers were exploiting a “massive” bug in MacOS that allowed them to push malware that bypassed vortually all of Apple's security mechanisms on its operating system. Researchers found one hacking group exploiting the bug since January of this year. https://www.vice.com/...
  • @zackwhittaker Zack Whittaker on x
    “All the user would need to do is double click — and no macOS prompts or warnings are generated,” @cedowens, who discovered the bug, told me. His proof of concept opened Calculator, but a malicious actor could use the same bug to steal user data. More: https://techcrunch.com/... …
  • @zackwhittaker Zack Whittaker on x
    New: Apple has fixed a zero-day security vulnerability that allowed the notorious Shlayer malware to bypass most of macOS' in-built security protections. https://t.co/Q0j63hdSAg
  • @atomicbird @atomicbird on x
    Apple, please stop checking the “enable Siri” box after every macOS update. I will never, ever enable it on a Mac. Stop trying to trick me into turning it on.
  • @__tosh Thomas Schranz on x
    Safari in macOS 11.3 now supports WebM and Vorbis https://support.apple.com/... https://twitter.com/...