Magazine

Apple Accidentally Verified a Malware MacOS App

Posted on the 01 September 2020 by Thiruvenkatam Chinnagounder @tipsclear
Apple Accidentally Verified a Malware MacOS App

A malware Mac package got past Apple's verification process, according to a new report. According to security researcher Patrick Wardle, Apple accidentally approved a malicious desktop app disguised as an Adobe Flash installer to trick users.

With Apple, Mac users can install apps from sources outside their own app store. However, to ensure this policy does not infect Macs with viruses and malware, the company has a process called "notarization" that scans apps for security issues. Developers must submit their code for approval prior to distribution. If an app fails this verification phase, Mac's built-in verification program Gatekeeper automatically blocks it - regardless of where it was downloaded from.

Wardle discovered that a popular malware called Shlayer, which security firm Kaspersky named the number one threat to Macs in 2019, contained snippets of code that had been officially notarized by Apple. As a result, when someone downloads this and tries to run it on their Mac, they won't be notified of any alerts. Shlayer is adware that can intercept your web traffic and replace the web pages you want to load with your own malicious ads.

Apple's verification process failed to detect the malware and gave the green light to run on all macOS versions, even Big Sur, which is currently in beta.

"As far as I know, this is a first: malicious code that has received the notarized" seal of approval "from Apple," wrote Wardle in the blog post.

Since it was reported, Apple has patched and revoked the notarized payload. Soon after, however, the same group of attackers released a new notarized package - which Apple confirmed had also been banned.

"Malicious software is constantly changing, and Apple's notary system helps us keep malware off the Mac and react quickly if it is detected," commented Apple in a statement on Digital Trends. "When we heard about this adware, we revoked the variant we identified, deactivated the developer account, and revoked the associated certificates. We thank the researchers for their help in keeping our users safe. "

Editor's recommendations


Back to Featured Articles on Logo Paperblog