Impact
An application can bypass macOS Gatekeeper, a security feature that verifies code signatures before execution. The bypass allows unsigned or improperly signed software to run without prompting the user, effectively enabling malicious code to execute. The weakness is an improper access control that lets authorized applications circumvent the system’s security checks.
Affected Systems
The issue affects macOS releases prior to Golden Gate 27. Apple addressed it in macOS Golden Gate 27 by improving checks, so systems running older versions may be vulnerable to Gatekeeper bypass.
Risk and Exploitability
Exploit potential relies on delivering a malicious or modified application that bypasses Gatekeeper. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the criticality of allowing unsigned code execution warrants attention. The attack requires user or system execution of the malicious app, but the bypass removes the usual safeguards, increasing the risk of compromise. Upgrading to macOS Golden Gate 27 or later mitigates this risk.
OpenCVE Enrichment