Old Gatekeeper bypass vulnerability in macOS exploited
THREAT LEVEL: Amber
For a detailed advisory, download the pdf file here
A gatekeeper bypass vulnerability exists in macOS Big Sur and has been assigned CVE-2021-30853. An attacker can exploit this issue by using a specially-crafted script-based application downloaded from the Internet. This allows an attacker to launch the application without displaying an alert while being automatically quarantined. The specially-crafted application uses a script starting with a shebang (!#) character and leaving the rest of the line empty, which tells the Unix shell to run the script without specifying a shell command interpreter. This bug bypasses not just Gatekeeper, but also File Quarantine, and macOS’s recent notarization requirements. It affects the macOS Big Sur versions up to 11.5.2 and has been fixed in version 11.6
Vulnerability Details
Patch Link
https://support.apple.com/en-us/HT212804
References
https://thehackernews.com/2021/12/expert-details-macos-bug-that-could-let.html
https://objective-see.com/blog/blog_0x6A.html
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox