🚨 We're disclosing a macOS security bug that Apple says is not an issue.
Using a simple archive-and-restore trick, an attacker can silently replace the main executable of virtually any application downloaded from the web—no password or warning is required.
Here's a demo using Signal to steal its encryption key.
📝 Blog with technical details: link in the replies.
Do you think this should be considered a security bug?
🎬👇
#Apple #privacy #infosec #security #macOS

youtu.be/0bOC8S3NQxI

YouTubemacOS Security: Replacing Trusted App Executables (Demo with Signal)by Mysk

Replying to @⁨mysk@mastodon.social⁩

We made a few mockups showing how we think Apple could improve macOS permission prompts to make app-tampering attacks far less effective:

2) Show a clear warning if macOS detects that an app’s signing identity has changed since it was last opened.

Simple changes like these could make it much harder for attackers to trick users into granting sensitive permissions.

1) Display the developer’s signing identity in TCC permission dialogs and when an app is opened for the first time.
ALT
1) Display the developer’s signing identity in TCC permission dialogs and when an app is opened for the first time.
ALT
2) Show a clear warning if macOS detects that an app’s signing identity has changed since it was last opened.
ALT