Executive brief
A security flaw in macOS could allow a malicious application to bypass Gatekeeper, the system's built-in security feature that ensures only trusted software runs on your Mac. If exploited, an unauthorized app could execute on the system without the usual security warnings or quarantine checks. This could lead to the installation of malware or unauthorized access to the device.
Technical details
A vulnerability in the macOS file quarantine mechanism allowed applications to bypass Gatekeeper security checks. Gatekeeper is designed to enforce code signing and verify downloaded applications before execution; this flaw permitted a bypass of those integrity and origin checks. The root cause was insufficient validation during the quarantine process, which Apple addressed by implementing additional checks. An attacker would likely need to entice a user to download and attempt to run a specially crafted application. Patches are available in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, and macOS Tahoe 26.6.
Affected products
- Apple macOS Sequoia Before 15.7.8
- Apple macOS Sonoma Before 14.8.8
- Apple macOS Tahoe Before 26.6
Timeline
- 2026-07-27: disclosed
- 2026-07-27: patched