Shlayer macOS malware abuses zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1810 | A logic issue was addressed with improved state management. A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2021-30657 | Actively Exploited Gatekeeper Bypass in Apple macOS CVE-2021-30657 is a logic flaw (CWE-862) in macOS whose faulty state management allows a malicious application to bypass Gatekeeper, Apple's mechanism that verifies and prompts users before first launch of downloaded software. It is triggered locally when a user opens a malicious, quarantined application; the flawed state handling lets the app launch without the expected Gatekeeper authorization checks. An attacker gains the ability to run unsigned or unnotarized code without the usual security warning, which in observed campaigns enabled adware families such as AdLoad to install on user-level accounts. Any Mac running a version of macOS Big Sur prior to 11.3, or macOS Catalina without Security Update 2021-002, is affected. Apple confirmed the issue was being actively exploited in the wild, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog. Do: Upgrade to macOS Big Sur 11.3 or later, or apply Security Update 2021-002 Catalina (or newer) per Apple's instructions, then verify the installed version under Apple menu > About This Mac. Because the flaw lets quarantined apps launch without a Gatekeeper prompt, scrutinize downloaded applications and monitor for AdLoad adware indicators on endpoints that have not yet been patched. This CVE is in CISA KEV, so federal and KEV-tracked environments must apply the vendor updates by the required action deadline. | 5.5 | 69% | KEV |
| mass≈100M+ Macs running affected Big Sur or Catalina builds at the time of disclosure |
Full article425 words · extracted from securityaffairs.com · click to collapse

Apple addresses a zero-day in macOS exploited by Shlayer malware to bypass Apple’s security features and deliver second-stage malicious payloads.
Apple has addressed a zero-day flaw in macOS that was exploited by Shlayer malware to bypass Apple’s File Quarantine, Gatekeeper, and Notarization security checks and download second-stage malicious payloads.
The developers behind the Shlayer malware have successfully managed to get their malicious payloads approved by Apple through its automated notarizing process in order to run on macOS.
Developers have to scan their software for macOS through the automated Apple’s notary service in order to have a green light from the Gatekeeper security feature.
In January 2020, security experts from Kaspersky Lab revealed that the Shlayer malware was the most widespread macOS threat in 2019. Over the years, the malware was continuously improved, it was able to escalate privileges and disable the Gatekeeper feature to run unsigned second-stage malware.
According to the Jamf Protect detection team, early this year threat actors behind the Shlayer malware created unsigned and unnotarized Shlayer samples that exploit a zero-day vulnerability (tracked as CVE-2021-30657). The flaw is a logic issue that could allow the malicious code to bypass Gatekeeper checks.
“Shlayer malware detected allows an attacker to bypass Gatekeeper, Notarization and File Quarantine security technologies in macOS. The exploit allows unapproved software to run on Mac and is distributed via compromised websites or poisoned search engine results.” reads the post published by Jamf Protect.
The latest variant of the malware is being distributed using black SEO and compromised websites, it can be easily executed by simply double-clicking on the malicious file. Experts pointed out that the new variant doesn’t require the right-click method for its execution because the malware comes packaged in the format required to abuse CVE-2021-1810.
Apple has released security to address the vulnerability in macOS Big Sur 11.3 and to prevent the malware from spreading. Once installed the updates, macOS users that will double click on the file will display a message informing them that the app cannot be opened because the developer cannot be identified.
“Since the malicious application is not notarized or signed with a valid developer’s certificate, the message will prompt the user to eject the mounted DMG containing the app bundle.” continues the post.
Jamf also published Indicators of Compromise for this threat.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Mac OS zero-day)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/117262/malware/shlayer-macos-zero-day.html