Resource icon

Mac app notarization: a known-malware check, not a guarantee

What the term means​

Apple's notarization process checks submitted Mac software for known malicious content. A notarized app also has a developer signature used to check that the file has not been altered since signing. This adds a useful distribution signal to Gatekeeper; it does not promise that all future behavior, privacy practices or updates are harmless.

A useful distinction​

A developer may say “Apple notarized” on a download page. That statement is not itself verification that the file you downloaded is the submitted build or that the page belongs to the developer. Prefer the official download route and let macOS perform its own checks when you open the actual file. Be skeptical when instructions start by disabling security controls.

How to use the signal​

Apple's safe-opening explanation says notarization indicates that Apple checked for known malware and none was detected. Its code-signing guide distinguishes a signature's integrity check from notarization's malware check. If an app fails a check, pause and investigate the publisher rather than treating a prominent download button as proof of safety.
Posted by
Jack
Views
4
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack