Particle.news
Download on the App Store

Researchers Demonstrate How Web‑Downloaded macOS Apps Can Be Silently Replaced

Apple says the technique reflects user‑driven behavior that falls outside Gatekeeper’s protections.

Overview

  • Two security researchers published a method that can replace the main executable inside an app downloaded from the web so the app later runs attacker‑controlled code while still appearing trusted.
  • The technique works only after a precise sequence: the app is downloaded and run, the app bundle is archived and the original deleted, and the archived copy is extracted back onto the Mac without triggering a Gatekeeper recheck.
  • Researchers and outlets stress the attack requires prior local access or code execution on the user account, making it a post‑compromise or social‑engineering pathway rather than a remote, privilege‑escalation flaw.
  • Apple reviewed the report and considers rebuilt or locally restored app bundles outside Gatekeeper’s scope, so it does not treat this behavior as a security bug and has not announced an OS fix.
  • Practical advice for users is to prefer the Mac App Store or direct developer downloads, avoid archiving and re‑extracting installed apps when possible, and re‑download apps you suspect may have been tampered with.