Skip to main content

Digital Trends may earn a commission when you buy through links on our site. Why trust us?

This critical macOS flaw may leave your Mac defenseless

Apple’s macOS operating system has such a strong reputation for security that many people mistakenly believe Macs simply aren’t affected by malware. Well, Microsoft has served up a reminder that that’s not true, as the company has identified a serious vulnerability that affects one of macOS’s most important lines of defense.

According to Bleeping Computer, the bug was first reported by Jonathan Bar Or, Microsoft’s principal security researcher, who named the flaw Achilles. It is now tracked as CVE-2022-42821.

A close-up of a MacBook illuminated under neon lights.

In simple terms, Achilles works by bypassing macOS’s Gatekeeper feature. Whenever a user downloads a Mac app, plugin, or installer that is not from Apple’s App Store, Gatekeeper checks that it is from a verified developer, is notarized by Apple to be free of malware, and hasn’t been altered. If the app passes those checks, it can run on the user’s Mac. If it fails, Gatekeeper blocks it.

Achilles, however, found a way around this protection. As laid out in a recent Microsoft blog post, macOS assigns an extended attribute called com.apple.quarantine to apps downloaded using internet browsers. Among other things, this attribute tells macOS that Gatekeeper should check the file before it can be installed.

Achilles blocks the assignment of this attribute. That means a malicious file will be able to run on macOS without ever triggering Gatekeeper, thereby side-stepping Apple’s built-in security protections.

Interestingly, Microsoft says macOS’s Lockdown Mode is no use in fighting Achilles because it is designed to solve a different problem. Lockdown Mode is a special high-security mode in macOS that protects individuals who are vulnerable to highly sophisticated cyberattacks — think journalists in repressive states, for example. Regardless of your Lockdown Mode status, you should update macOS to protect against Achilles.

The security flaw was originally discovered by Microsoft in July 2022, and was fixed by Apple in macOS 13 (Ventura), macOS 12.6.2 (Monterey), and macOS 11.7.2 (Big Sur). It highlights the importance of keeping macOS up to date to ensure you have the latest security patches and fixes.

It’s not the first time Microsoft has spotted a macOS vulnerability and helped Apple fix it. In February 2022, for example, Microsoft issued a warning about a macOS trojan called UpdateAgent. Interestingly, this malware could also get around Gatekeeper. It shows that while Gatekeeper is an excellent piece of defensive software, it’s not bulletproof.

Editors' Recommendations

Alex Blake
In ancient times, people like Alex would have been shunned for their nerdy ways and strange opinions on cheese. Today, he…
Apple’s macOS Sonoma has a game-changing feature — literally
apple could fix mac game porting wwdc 2023 gaming 1

Apple’s Worldwide Developers Conference (WWDC) was chock-full of new announcements, and it’s fair to say that between the Vision Pro headset and all of Apple’s new Macs, macOS was far from the biggest new reveal. Yet, there was one new macOS feature that could be absolutely game-changing.

That’s because right now, Mac gaming is in a pretty bad way. Gamers don’t buy Macs because there aren’t enough good games, and developers don’t port their games to the Mac because there aren’t enough people to play them. It’s a chicken-and-egg situation caught in a death spiral.

Read more
This critical exploit could let hackers bypass your Mac’s defenses
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

Microsoft has discovered a critical exploit in macOS that could grant hackers easy access to your Mac’s most important data. Dubbed ‘Migraine,’ it shows why it’s vital to update your Mac as soon as possible.

Migraine is so damaging because it can bypass Apple’s System Integrity Protection, or SIP for short. SIP is enabled by default on modern Macs and works by sandboxing sensitive parts of the computer from outside meddling. Only processes that are signed by Apple (or those with special privileges, like Apple installers) are allowed to alter something guarded by SIP.

Read more
This macOS concept fixes both the Touch Bar and Dynamic Island
Concept of macOS dynamic dock.

What if your macOS dock behaved more fluidly, dynamically morphing to show background processes such as download progress, media controls, text messages, and so on?

The following concepts demonstrate "what if" macOS and iOS Live Activities got together and had a child, and they have certainly got my imagination going.

Read more