Researchers replace downloaded macOS apps with evil twins, Apple shrugs
Summary
Researchers have demonstrated a new attack on macOS that replaces downloaded applications with malicious "evil twin" versions. This exploit bypasses Apple's Gatekeeper security feature, allowing attackers to potentially install unauthorized software. Apple has reportedly acknowledged the issue but has not yet implemented a fix.
IFF Assessment
This article describes a new vulnerability and exploit that can be used to compromise user systems, representing bad news for defenders.
Defender Context
This exploit highlights a significant weakness in macOS Gatekeeper's ability to protect users from malicious downloads. Defenders should be aware of this attack vector and encourage users to be extra cautious about application sources, especially for applications downloaded from unofficial channels. It also points to the ongoing challenge of keeping security features effective against evolving attacker techniques.