Search This Blog

Powered by Blogger.

Blog Archive

Labels

PoC Exploit Code Published for macOS Gatekeeper Bypass Vulnerability

The vulnerability was spotted in the Archive Utility component of macOS Big Sur and Catalina.

 

Cybersecurity researcher Rasmus of F-Secure has published a proof-of-concept (PoC) exploit code for a macOS Gatekeeper bypass vulnerability that Apple fixed earlier this year in April. 

The PoC exploit code targets CVE-2021-1810, a flaw that can lead to the bypass of all three protections that Apple executed against downloading malicious files in macOS – file quarantine, Gatekeeper, and notarization. 

The vulnerability was spotted in the Archive Utility component of macOS Big Sur and Catalina and can be abused via a specially designed ZIP file. To successfully exploit the flaw, an attacker must trick a user into installing and opening an archive to implement malicious code inside. 

By exploiting the flaw, the attacker can implement unsigned binaries on macOS devices, even if the Gatekeeper enforces code signing or warn user of the malicious code implementation . According to Sten, the flaw is related to the way in which the Archive Utility handles file paths. Particularly, for paths longer than 886 characters, the com.apple.quarantine extended attribute would no longer apply, resulting in a Gatekeeper bypass for the files. 

While researching edge cases with long path filenames, the researcher identified that some macOS components acted surprisingly when the total path length reached a certain limit. Finally, Sten identified that it was feasible to design an archive with a hierarchical structure for which the path length was long enough so that Safari would call Archive Utility to unpack it and that Archive Utility would not apply the com.apple.quarantine attribute, but short enough to be browsable using Finder and for macOS to execute the code within. 

“In order to make it more appealing to the user, the archive folder structure could be hidden (prefixed with a full stop) with a symbolic link in the root which was almost indistinguishable from a single app bundle in the archive root,” the researcher explained in his blog post. 

The researcher also published a video demo of the exploit that creates the archive with the path length necessary to bypass CVE-2021-1810, along with a symbolic link to make the ZIP file look normal. The flaw was addressed with the release of macOS Big Sur 11.3 and Security Update 2021-002 for Catalina.
Share it:

macOS Products

Malicious Codes

PoC Exploit Code

Vulnerabilities and Exploit