News: 1671564610

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft reports macOS Gatekeeper has an 'Achilles' heel

(2022/12/20)


Security researchers at Microsoft have discovered a bug in macOS that lets malicious apps bypass Apple's Gatekeeper security software "for initial access by malware and other threats."

Dubbed "Achilles," (which sounds sexier than [1]CVE-2022-42821 ) Microsoft researchers said the vulnerability was discovered in late July, and quickly patched by Apple in all affected versions of its OSes after the team followed responsible disclosure.

Regardless of that fix, it's still critical for macOS users to patch their systems to the latest protected versions, Microsoft said, because Apple's much-touted Lockdown Mode isn't designed to protect against Achilles-style threats.

[2]

"End-users should apply the fix regardless of their Lockdown Mode status," Microsoft said.

How to distract a Gatekeeper

Gatekeeper has been a part of macOS for a decade and is used to validate that apps are signed and notarized before allowing them to be launched. If an app isn't recognized, Gatekeeper blocks it by default, though this can be overridden by a user that is willing to accept the risk.

With Achilles, however, Microsoft's proof of concept was able to take advantage of how macOS deploys access control lists (ACLs) to [3]completely bypass Gatekeeper .

[4]

[5]

Infections with macOS are often the result of users running malicious apps, Microsoft principal security researcher Jonathan Bar Or wrote in the company's [6]report on the bug. He said that Apple has imposed "strong security mechanisms" on macOS to combat the use of disguised malware or legitimate-but-infected apps

Apple does that by assigning a special extended attribute to files that it uses to enforce certain policies, like Gatekeeper quarantines. But in the course of researching recent Gatekeeper bypasses the team noticed two common approaches: misusing extended attributes and finding vulnerabilities in policy check enforcers that quarantine files.

[7]Apple patches iPhone and macOS flaws under active attack

[8]Microsoft squashes six security bugs already exploited in the wild

[9]Microsoft fixes under-attack Windows zero-day Follina

[10]Patch now: Zoom chat messages can infect PCs, Macs, phones with malware

A closer look at one particular vulnerability reported in 2021 led the researchers to turn to archive files as a method of bypassing Gatekeeper, and they found one in the form of AppleDouble binaries, which save metadata in a separate file.

When AppleDouble files are extracted by macOS, they found, all of the file's extended attributes are also restored. Slip in the right extended attribute by using the xattr command, like a modified ACL, and you have a way to tell Gatekeeper that whatever it's looking at definitely isn't the file it's looking for, Bar Orr said.

[11]

"Our data shows that fake apps remain one of the top entry vectors on macOS, indicating Gatekeeper bypass techniques are an attractive and even a necessary capability for adversaries to leverage in attacks," Bar Or wrote.

Lockdown Mode, schmockdown mode

Apple claimed in July that Lockdown Mode was so secure, and the company so confident in its capabilities, that it was [12]doubling its bug bounty payouts to a max of $2 million for Lockdown Mode compromises.

Lockdown Mode is described by Apple as for a small number of users whose lives and/or work make them targets for digital threats. The optional mode is designed to fight government-sponsored spyware kits like Pegasus by blocking attachments, disabling some web technologies, blocking FaceTime calls, not allowing wired connections and blocking installation of configuration profiles and MDM software.

Sneaking malicious code in through a compromised binary is, unfortunately, not one of Lockdown Mode's features, though Apple said it plans to add features over time - hopefully a stronger Gatekeeper makes the cut.

Unfortunately for Bar Or and Microsoft, Achilles doesn't qualify for a Lockdown Mode bounty of any size. "Lockdown Mode is not intended to deal with this class of exploits, so it won't stop it," Bar Or told us. ®

Get our [13]Tech Resources



[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42821

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y6I@j6cykDgCNYUUGwFVUAAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.microsoft.com/en-us/videoplayer/embed/RE5dQo5

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6I@j6cykDgCNYUUGwFVUAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y6I@j6cykDgCNYUUGwFVUAAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/

[7] https://www.theregister.com/2022/09/12/apple_patched_exploited_flaws/

[8] https://www.theregister.com/2022/11/09/microsoft_november_2022_patch_tuesday/

[9] https://www.theregister.com/2022/06/15/microsoft_patch_tuesday/

[10] https://www.theregister.com/2022/05/24/zoom_rce_bug_patched/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y6I@j6cykDgCNYUUGwFVUAAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2022/07/06/apple_lockdown_mode/

[13] https://whitepapers.theregister.com/



I detect a trend here

Will Godfrey

Microsoft seems very cough public spirited cough in pointing out everyone else's bugs.

Re: I detect a trend here

IGotOut

Just like Google and Apple?

Re: I detect a trend here

jake

And everybody else.

Good thing. NO company wants to announce their own bugs. This way, we (us GreatUnwashed) get to see things that might otherwise be swept under the rug.

Insert your Trojan joke here

milliemoo83

Well if we built this giant wooden badger....

Re: Insert your Trojan joke here

jake

We don' need no steenkin' badgers!

My word, what a conveniently timed release..

Anonymous Coward

.. given that their own bugs [1]nuked customer machines .

It appears Redmond is desperately in need of some distraction?

BTW, I did check, the specific CVE appears to have been addressed a week ago (13 December).

[1] https://www.theregister.com/2022/12/20/microsoft_windows_10_crash/

Re: My word, what a conveniently timed release..

jake

"the specific CVE appears to have been addressed"

Yes. That's why it's being announced now, not earlier. There is indeed a fix. Have you applied it yet? Did you even know it was available? Good thing Microsoft put it in the spotlight, no? ... Apple sure as hell wasn't going to announce it to all and sundry!

A couch is as good as a chair.