Silent Replacement of Trusted macOS App Executables Without Admin Privileges

Silent Replacement of Trusted macOS App Executables Without Admin Privileges

I discovered a macOS vulnerability allowing attackers to silently replace trusted app executables downloaded from the web. By archiving and restoring an app bundle, malicious code can run under the guise of legitimate software like Signal or Slack. This method bypasses security warnings and tricks users into granting access to sensitive data, yet Apple has decided not to issue a fix for this behavior.

We found a macOS security issue that Apple looked into but decided not to fix.

More from this day

2026-07-23