Silent Replacement of Trusted macOS App Executables
Summary
Researchers disclose a macOS vulnerability that lets attackers silently replace the main executable of apps downloaded from the web, bypassing prompts and potentially accessing Keychain data and TCC-protected folders. The post includes a PoC, Apple's stance, and remediation suggestions, highlighting the trust users place in signed apps and practical mitigations for individuals and SMBs.