This severe macOS flaw could let malware run on your Mac — update right now (2024)

This severe macOS flaw could let malware run on your Mac — update right now (1)

A critical security flaw has been discovered in macOS which could be exploited by hackers to install malware on vulnerable MacBooks, Macs and other Apple computers.

As reported by BleepingComputer, the vulnerability (tracked as CVE-2022-42821) and dubbed ‘Achilles’ was first discovered by principal security researcher at Microsoft, Jonathan Bar Or back in July of this year. However, we’re only hearing about it now as Apple patched this vulnerability earlier this month.

If you haven’t updated your MacBook, iMac, Mac mini or other Apple computers yet, you should do so immediately as hackers often like to target vulnerable machines – especially after the discovery of a major vulnerability. Even if you’re not running macOS 13 yet, Apple has released security patches to address the issue for older versions of its operating system including macOS Monterey 12.6.2 and macOS Big Sur 11.7.2.

Bypassing Gatekeeper

Just like how Microsoft includes its own antivirus software in the form of Microsoft Defender with Windows 10 and Windows 11, Apple ships Gatekeeper and XProtect with every version of macOS. While Gatekeeper ensures every new piece of software you download for your Mac is verified before it's installed, XProtect scans your Mac for malware.

When you download a new app for your Mac using a web browser, Apple “assigns a special extended attribute to the downloaded file” according to a blog post from Microsoft Security Threat Intelligence. This attribute (com.apple.quarantine) is used by Gatekeeper to let it know that the new app needs to be checked to see if it was approved by Apple (developer-signed) before it can be installed. If a new app fails this check, macOS informs the user that it can’t be run since it’s untrusted.

By exploiting the Achilles flaw in macOS though, specially-crafted payloads are able to abuse a logic issue and bypass Gatekeeper’s security protections. As such, malicious apps can be installed on a Mac.

In its blog post, Microsoft also points out that Apple’s new Lockdown Mode may be capable of protecting targeted users from sophisticated attacks but the feature can’t defend against Achilles.

Sign up to get the BEST of Tom’s Guide direct to your inbox.

Upgrade your life with a daily dose of the biggest tech news, lifestyle hacks and our curated analysis. Be the first to know about cutting-edge gadgets and the hottest deals.

How to protect your Mac from malware and other threats

This severe macOS flaw could let malware run on your Mac — update right now (2)

As we mentioned above, the first thing you should do to protect your Mac against malware spread using the Achilles flaw is to update to the latest version as Apple has since released a fix for this vulnerability.

From here, you may want to consider installing one of the best Mac antivirus software solutions for additional protection. Macs have historically been safer than PCs but as more people switch from Windows to macOS, cybercriminals have begun tailoring their malware and other viruses to target Mac users instead.

Even though Achilles has now been patched, we’ll likely continue to hear about this macOS flaw as hackers and other cybercriminals will look to capitalize on Mac users that didn’t update their systems to defend against it.

This severe macOS flaw could let malware run on your Mac — update right now (3)

Anthony Spadafora

Senior Editor Security and Networking

Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.

More about malware adware

This new Android banking trojan impersonates Chrome to steal your money — how to stay safeHackers are using this little-known file type to drop a nasty Windows worm on vulnerable PCs — how to stay safe

Latest

I challenged Gemini Flash 1.5 in AI studio with 3 prompts — its better than the app
See more latest►

No comments yetComment from the forums

    Most Popular
    Today's NYT Connections hints and answers — Thursday, June 27, #382
    7 best mobile AI apps for iPhone and Android
    New on Netflix in July 2024 — all the new shows and movies you need to watch
    How to watch 'Douglas Is Cancelled' online from anywhere
    Samsung Galaxy S25 chipset rumor is shockingly bold
    SA vs AFG live stream: how to watch T20 World Cup 2024 semi final online
    Apple AirPods can be hacked to eavesdrop on your conversations — how to stay safe
    Google confirms a major change to search that undoes a 2-year-old decision
    Forget Temu — Amazon reportedly building new discount section that ships directly from China
    'Emily in Paris' season 4 adds hunky new cast member —is he Emily's new love interest?
    Google Pixel 9 Pro Fold — all the rumors so far
    This severe macOS flaw could let malware run on your Mac — update right now (2024)

    References

    Top Articles
    Latest Posts
    Article information

    Author: Chrissy Homenick

    Last Updated:

    Views: 5815

    Rating: 4.3 / 5 (54 voted)

    Reviews: 85% of readers found this page helpful

    Author information

    Name: Chrissy Homenick

    Birthday: 2001-10-22

    Address: 611 Kuhn Oval, Feltonbury, NY 02783-3818

    Phone: +96619177651654

    Job: Mining Representative

    Hobby: amateur radio, Sculling, Knife making, Gardening, Watching movies, Gunsmithing, Video gaming

    Introduction: My name is Chrissy Homenick, I am a tender, funny, determined, tender, glorious, fancy, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.