Executive brief
Apple's Gatekeeper is a security feature that prevents users from running potentially malicious applications and files downloaded from the internet. This vulnerability allows an attacker to bypass Gatekeeper protections by crafting a malicious archive file, potentially allowing unauthorized code execution. The bypass could enable distribution of malware disguised as legitimate software across macOS and iOS platforms.
Technical details
This vulnerability is a file quarantine bypass in Apple's Gatekeeper mechanism, which validates and permits execution of downloaded files. An archive file can be specially crafted to evade Gatekeeper's file validation checks, allowing the contained malicious executable to execute without proper security review. The vulnerability affects multiple Apple platforms through a design flaw in how Gatekeeper handles archived files. The issue has been addressed with additional validation checks in the patched versions. No user interaction beyond attempting to run the archive contents is required after initial download.
Affected products
- Apple iOS before 26.7 and before 27
- Apple iPadOS before 26.7 and before 27
- Apple macOS Golden Gate before 27
- Apple macOS Sequoia before 15.8
- Apple macOS Tahoe before 26.7
- Apple visionOS before 27
- Apple watchOS before 27
Timeline
- 2026-09-14: patched: iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27
- 2026-09-14: advisory