Executive brief
Gatekeeper is macOS's security feature that prevents users from running unverified or untrusted applications. A logic flaw allows an attacker to craft a malicious app that bypasses these checks, enabling execution of unauthorized code on a user's machine without security warnings. This could allow installation and execution of malware, ransomware, or spyware with full system access.
Technical details
The vulnerability is a logic issue in LaunchServices, the macOS component responsible for validating applications against Gatekeeper security policies. The root cause is insufficient validation during the Gatekeeper enforcement process. An attacker can craft a specially designed application that exploits this logic flaw to bypass the security checks that normally prevent execution of untrusted or unsigned binaries. The vulnerability requires the user to attempt to execute the malicious application, but does not require elevated privileges or network access. A successful exploit allows arbitrary code execution in the context of the user. Patches are available in macOS Sequoia 15.7.4 and macOS Tahoe 26.2.
Affected products
- Apple macOS Sequoia before 15.7.4
- Apple macOS Tahoe before 26.2
Timeline
- 2025-12-17: disclosed
- 2025-12-12: patched: macOS Tahoe 26.2
- 2026-02-11: patched: macOS Sequoia 15.7.4