Microsoft finds macOS bug that lets malware bypass security checks

enaph

Level 30
Thread author
Verified
Honorary Member
Top Poster
Well-known
Forum Veteran
Jun 14, 2011
1,843
2
12,358
2,879
Null Island
Apple has fixed a vulnerability attackers could leverage to deploy malware on vulnerable macOS devices via untrusted applications capable of bypassing Gatekeeper application execution restrictions.

Found and reported by Microsoft principal security researcher Jonathan Bar Or, the security flaw (dubbed Achilles) is now tracked as CVE-2022-42821.

Apple addressed the bug in macOS 13 (Ventura), macOS 12.6.2 (Monterey), and macOS 1.7.2 (Big Sur) one week ago, on December 13.
 
This only affected Monterey and Big Sur. Not Ventura?

11 - Big Sur
12 - Monterey

Screenshot 2022-12-20 at 23.05.32.png

Image credit: NVD - CVE-2022-42821