Login to view this video
Browse and search by keywords or use filters to find sessions that interest you most. Stay tuned as more sessions are added regularly.
Bypassing the Gate: A Deep Dive Into Gatekeeper Flaws in macOS
Gatekeeper is an essential component of macOS security, ensuring that only trusted software runs on the system by verifying code signing and notarization information. Over the years, we have observed macOS malware bypassing Gatekeeper controls, overriding them or even leveraging valid developer IDs to achieve unauthorized code execution. It is crucial for defenders to understand the techniques attackers use to deploy malware on macOS.
In this talk, we will introduce Gatekeeper and delve into some of its internals to better understand its functionality. We'll examine Gatekeeper's role concerning various malware strains found on macOS. We will also share insights from our discovery process for some of these vulnerabilities. We plan to analyze three specific Gatekeeper bypasses that we've reported to Apple:
As a bonus, we will also examine Gatekeeper bypasses in third-party software, including CVE-2023-46270 and CVE-2024-22405.
Join us as we explore the internals of macOS and unveil several unique Gatekeeper vulnerabilities. Our findings demonstrate the execution of entirely unsigned and un-notarized applications, effectively bypassing Gatekeeper’s checks. To conclude, we will provide high-level detection strategies to counter these threats, utilizing Apple’s Endpoint Security API.
In this talk, we will introduce Gatekeeper and delve into some of its internals to better understand its functionality. We'll examine Gatekeeper's role concerning various malware strains found on macOS. We will also share insights from our discovery process for some of these vulnerabilities. We plan to analyze three specific Gatekeeper bypasses that we've reported to Apple:
- CVE-2022-22616: A flaw in the BOM framework and Safari
- CVE-2022-32910: A flaw in Archive Utility
- CVE-2023-41067: A flaw in Launch Services
As a bonus, we will also examine Gatekeeper bypasses in third-party software, including CVE-2023-46270 and CVE-2024-22405.
Join us as we explore the internals of macOS and unveil several unique Gatekeeper vulnerabilities. Our findings demonstrate the execution of entirely unsigned and un-notarized applications, effectively bypassing Gatekeeper’s checks. To conclude, we will provide high-level detection strategies to counter these threats, utilizing Apple’s Endpoint Security API.
Speakers
FS
Staff Security Researcher, Jamf
Session Type: Breakout Session
Products: Jamf Protect
Audience: Commercial, Government, Higher Education, K-12 Education, Healthcare - Commercial, Healthcare - Education
Skill Level: Level 400