Hackers abused a macOS security hole to infect users via poisoned search results MacBook


If you haven’t updated to the latest version of macOS yet, now is the time to do so as security researchers have identified a new campaign that uses fake application bundles to install malware on the Macs of unsuspecting users.
In a recent blog post, the mac malware specialists at Objective-See described an exploit that could allow an attacker to create a fake application bundle using a script as the primary executable in order to bypass File Quarantine, Gatekeeper and Notarization on macOS.
While this exploit only works on versions of macOS before 11.3, the detections team at Jamf Protect has observed this exploit being used in the wild by a variant of the Shlayer malware used to drop adware. This new variant has also been repackaged to use a format necessary for carrying out the Gatekeeper bypass vulnerability.
One of the ways in which this campaign is spread is via poisoned search results. Cybercriminals often create fake webpages and hijack the results of search engines in order to spread malware and other viruses. This is why users must remain vigilant online even when using a legitimate search engine like Google.
Abusing Gatekeeper bypass
In order to abuse this vulnerability, an attacker would need to craft an application bundle using a script as the main executable and not create an Info.plist file. This application would then need to be placed into a dmg file for distribution. When the dmg is mounted and double clicked, the combination of a script-based application with no Info.plist file executes without any quarantine, signature or notarization verification.
Updating your Mac to the latest version of macOS is the easiest way to prevent falling victim to any attacks launched using this method as this vulnerability was patched with the release of macOS version 11.3 earlier today. If a user tries to execute the Shlayer malware on a patched version of macOS, they will see a pop-up which says that the software “cannot be opened because the developer cannot be identified”.
While macOS users running the latest version of Apple’s operating system are protected for now, the detections team at Jamf Protect makes the point in a new blog post that “Shlayer continues to reintroduce itself with innovative ways to infect macOS-based systems”.
As Macs have become more prevalent in the workplace as business laptops, cybercriminals have taken notice and they are now actively developing Mac malware to infect even more users.
If you haven’t updated to the latest version of macOS yet, now is the time to do so as security researchers have identified a new campaign that uses fake application bundles to install malware on the Macs of unsuspecting users. In a recent blog post, the mac malware specialists at…
Recent Posts
- Severance opens up a new kind of terror in latest episode
- The OLED TV I want to buy in 2025 is last year’s LG C4 – here’s why
- DJI’s drone-in-a-box can now launch from moving vehicles
- Best iPad Accessories (2025), Tested and Reviewed
- We might have our first look at the Samsung Galaxy Z Flip 7, but I can’t tell the difference from the Z Flip 6
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010