{"id":237022,"date":"2021-04-27T22:50:01","date_gmt":"2021-04-27T19:50:01","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hackers-use-a-bug-to-evade-macos-defenses\/"},"modified":"2021-04-27T22:50:01","modified_gmt":"2021-04-27T19:50:01","slug":"hackers-use-a-bug-to-evade-macos-defenses","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hackers-use-a-bug-to-evade-macos-defenses\/","title":{"rendered":"#Hackers use a bug to evade macOS defenses"},"content":{"rendered":"<p>&#8220;<strong>#Hackers use a bug to evade macOS defenses<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/hackers-use-a-bug-to-e.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/hackers-use-a-bug-to-e.jpg\" data-sub-html=\"MacOS keyboard. Credit: Unsplash.com\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/hackers-use-a-bug-to-e.jpg\" alt=\"Hackers use a bug to evade MacOS defenses\" title=\"MacOS keyboard. Credit: Unsplash.com\" width=\"800\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                MacOS keyboard. Credit: Unsplash.com<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>Lauded for years as the system able to best prevent malware infection, macOS recently fell victim to an operating system vulnerability that hackers used to circumvent all of <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le&#8217;s system defenses.<\/p>\n<p>                                                                                Security researcher Cedric Owens discovered this bug in March 2021 while assessing Apple&#8217;s Gatekeeper mechanism, a safeguard that will only allow developers to run their software on Macs after registering with Apple and paying a fee. Moreover, the company requires that all applications undergo an automated vetting process to further protect against malicious software. <\/p>\n<p>Unfortunately, Owens uncovered a logic flaw in the macOS itself, rather than the defense systems. The bug allowed attackers to develop malware able to deceive the operating system into running their malware regardless of whether they passed Apple&#8217;s safety checks. Indeed, this flaw resembles a door that has been securely locked and bolted but still has a small pet door at the bottom through which you can break in or insert a bomb.<\/p>\n<p>Owens found that the bug worked by exploiting Apple&#8217;s assumption regarding all applications allegedly including a standard metadata file called &#8220;info.plist.&#8221; He soon realized he could easily craft malware that ran as a simple script, thus avoiding the multiple layers that trigger Apple&#8217;s Gatekeeper and enabling evil software to fly under the radar. In fact, he discovered that this evil code could run so stealthily that macOS wouldn&#8217;t even prompt the user for permission to download the app from the Internet. <\/p>\n<p>Further analysis showed that macOS does run a check to see whether the new application is notarized. However, if the system finds that the software bundle doesn&#8217;t include an &#8220;info.plist&#8221; file, the software passes the checkpoint. Once the researchers had confirmed the bug with Apple, they learned that the Apple-focused device management firm Jamf had, in fact, detected script-based malware that fit the criteria of this threat, soon finding that a version of Shlayer adware had already actively exploited the vulnerability.<\/p>\n<p>With the introduction of Gatekeeper in February 2020, cybercriminals have faced a significant obstacle due to the massive decrease in at-risk users, thanks to Apple&#8217;s enhanced defenses. However, groups like the attackers who developed Shlayer have had some luck tricking Apple into notarizing their malware. Using this method, hackers don&#8217;t even have to worry about macOS notifying users of a new application in the first place.<\/p>\n<p>In response, Apple has patched the bug in the macOS Big Sur 11.3 version. Additionally, the company has upgraded its XProtect system monitoring tool to identify and notify users regarding any software potentially trying to exploit this flaw.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Apple error approves MacOS malware\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                macOS Gatekeeper Bypass (2021 Edition): <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cedowens.medium.com\/macos-gatekeeper-bypass-2021-edition-5256a2955508\">cedowens.medium.com\/macos-gate \u2026 edition-5256a2955508<\/a><br \/>\nAbout the security content of macOS Big Sur 11.3: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/support.apple.com\/en-us\/HT212325\">support.apple.com\/en-us\/HT212325<\/a><\/p>\n<\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Hackers use a bug to evade macOS defenses (2021, April 27)<br \/>\n                                                 retrieved 27 April 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-04-hackers-bug-evade-macos-defenses.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-04-hackers-bug-evade-macos-defenses.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Hackers use a bug to evade macOS defenses&#8221; MacOS keyboard. Credit: Unsplash.com Lauded for years as the system able to best prevent malware infection, macOS recently fell victim to an operating system vulnerability that hackers used to circumvent all of Apple&#8217;s system defenses. Security researcher Cedric Owens discovered this bug in March 2021 while assessing&#8230;<\/p>\n","protected":false},"author":1,"featured_media":237023,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2021\/hackers-use-a-bug-to-e.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-237022","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/237022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=237022"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/237022\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/237023"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=237022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=237022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=237022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}