Executive brief
A security vulnerability in Apple's operating systems could allow a malicious file to bypass Gatekeeper, the security feature designed to ensure only trusted software runs on your device. By using a specially crafted disk image, an attacker could trick the system into running unauthorized software without the usual security warnings. This could lead to the installation of malware or unauthorized access to the device.
Technical details
A file quarantine bypass vulnerability exists in the Kernel component of multiple Apple operating systems. The flaw allows a maliciously crafted disk image (.dmg) to bypass Gatekeeper security checks, which are intended to verify the developer's identity and ensure the software hasn't been tampered with. The root cause was an insufficient check during the file quarantine process. An attacker could exploit this by convincing a user to open a specially crafted disk image, potentially leading to the execution of unsigned or malicious code. Apple addressed the issue by implementing additional validation checks in iOS 18.7.9, iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, and macOS Tahoe 26.5.
Affected products
- Apple iOS Before 18.7.9
- Apple iPadOS Before 18.7.9
- Apple macOS Sequoia Before 15.7.7
- Apple macOS Sonoma Before 14.8.7
- Apple macOS Tahoe Before 26.5
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched
- 2026-05-11: advisory