Microsoft uncovers macOS flaw that could let malware run riot

Security attack
(Image credit: Shutterstock / ozrimoz)

Microsoft has revealed it discovered a major vulnerability in Apple’s macOS which could have allowed threat actors to bypass the operating system’s security protocols and run all kinds of malware on vulnerable endpoints

The vulnerability has since been shared with Apple and subsequently patched. 

In a blog post detailing the findings, Microsoft said that in late July its researchers discovered a way to bypass the Gatekeeper security mechanism and run untrusted apps on the target device. Gatekeeper is a security feature that enforces code signing and verifies downloaded applications before they are allowed to run.

Apple fixes the issue

Given Apple’s reliance on Gatekeeper to safeguard macOS users, Microsoft has dubbed the vulnerability “Achilles”. It notified the company of its findings through Coordinated Vulnerability Disclosure (CVD) via Microsoft Security Vulnerability Research (MSVR), and Apple “quickly” released a patch to all of the macOS versions.

Achilles is now being tracked as CVE-2022-42821, and is described on the CVE.mitre.org site as a “logic issue” that was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, and macOS Ventura 13, the site says. 

Microsoft also said the vulnerability can’t be eliminated with the use of Apple’s Lockdown Mode, suggesting that applying the patch is the only way forward. Lockdown Mode, introduced in macOS Ventura, is an optional protection feature for high-risk users, designed to stop zero-click remote code execution exploits. Therefore, Microsoft says, it does not defend against Achilles. 

“End-users should apply the fix regardless of their Lockdown Mode status,” the announcement reads. 

Gatekeeper may be a pivotal part of securing the macOS environment, but it’s not without its flaws, Microsoft said. Apparently, fake apps are one of the most popular attack vectors in the Apple ecosystem, suggesting that Gatekeeper bypass techniques are an “attractive and even necessary capability” for attackers. 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
A person in a wheelchair working at a computer.
Why betting on Mac security could put your organization at risk
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC