Security researchers Talal Haj Bakry and Tommy Mysk reported that macOS Gatekeeper can be bypassed after a web-downloaded application has been launched once, allowing an attacker with user-level code execution to replace the original app with a malicious lookalike without triggering a new authorization check. The technique reportedly works by archiving a previously validated application bundle and swapping in a malicious replacement, enabling silent substitution of commonly downloaded software such as Brave, Slack, Signal, and Visual Studio Code.
Apple's documentation says Gatekeeper is designed to verify that software from the internet is trusted before it runs, but the researchers said that trust is not re-evaluated in this replacement scenario once the app has already been approved. Apple reportedly closed the report, arguing that the proof of concept replaces the entire app bundle as a locally built app and therefore falls outside the protections it applies to downloaded software; the issue does not affect Mac App Store apps, but it raises concerns about post-installation tampering of third-party macOS applications.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Apple reportedly closed the researchers' report and said the proof of concept replaces the entire app bundle as a locally built app, which it does not treat as covered by the same macOS protections. Apple's support documentation describes Gatekeeper checks for software downloaded from the internet, including notarization and first-launch verification behavior.
Talal Haj Bakry and Tommy Mysk reported that macOS Gatekeeper can be bypassed for apps downloaded from the web after they have been run once, allowing a malicious replacement of the app without renewed authorization. The technique requires user-level code execution and does not affect Mac App Store apps, but could impact commonly downloaded apps such as Brave, Slack, Signal, and Visual Studio Code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetheregister.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.