This severe macOS flaw could let malware run on your Mac — update right now

MacBook Pro 16-inch 2021 sitting on a patio table

A critical security flaw has been discovered in macOS which could be exploited by hackers to install malware on vulnerable MacBooks, Macs and other Apple computers.

As reported by BleepingComputer, the vulnerability (tracked as CVE-2022-42821) and dubbed ‘Achilles’ was first discovered by principal security researcher at Microsoft, Jonathan Bar Or back in July of this year. However, we’re only hearing about it now as Apple patched this vulnerability earlier this month.

If you haven’t updated your MacBook, iMac, Mac mini or other Apple computers yet, you should do so immediately as hackers often like to target vulnerable machines – especially after the discovery of a major vulnerability. Even if you’re not running macOS 13 yet, Apple has released security patches to address the issue for older versions of its operating system including macOS Monterey 12.6.2 and macOS Big Sur 11.7.2.

Bypassing Gatekeeper

Just like how Microsoft includes its own antivirus software in the form of Microsoft Defender with Windows 10 and Windows 11, Apple ships Gatekeeper and XProtect with every version of macOS. While Gatekeeper ensures every new piece of software you download for your Mac is verified before it's installed, XProtect scans your Mac for malware.

When you download a new app for your Mac using a web browser, Apple “assigns a special extended attribute to the downloaded file” according to a blog post from Microsoft Security Threat Intelligence. This attribute (com.apple.quarantine) is used by Gatekeeper to let it know that the new app needs to be checked to see if it was approved by Apple (developer-signed) before it can be installed. If a new app fails this check, macOS informs the user that it can’t be run since it’s untrusted.

By exploiting the Achilles flaw in macOS though, specially-crafted payloads are able to abuse a logic issue and bypass Gatekeeper’s security protections. As such, malicious apps can be installed on a Mac.

In its blog post, Microsoft also points out that Apple’s new Lockdown Mode may be capable of protecting targeted users from sophisticated attacks but the feature can’t defend against Achilles. 

How to protect your Mac from malware and other threats

macOS security

(Image credit: Shutterstock)

As we mentioned above, the first thing you should do to protect your Mac against malware spread using the Achilles flaw is to update to the latest version as Apple has since released a fix for this vulnerability.

From here, you may want to consider installing one of the best Mac antivirus software solutions for additional protection. Macs have historically been safer than PCs but as more people switch from Windows to macOS, cybercriminals have begun tailoring their malware and other viruses to target Mac users instead.

Even though Achilles has now been patched, we’ll likely continue to hear about this macOS flaw as hackers and other cybercriminals will look to capitalize on Mac users that didn’t update their systems to defend against it.

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
MacBook Pro 2021 (16-inch) on a patio table
Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop.
Mac and iPhone users beware — Apple processors can be exploited to steal sensitive information
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Latest in Malware & Adware
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Malware
Dangerous new password-stealing trojan automatically reinstalls itself on infected PCs
An FBI agent typing on a computer
FBI issues warning to millions of Americans to avoid these websites that can steal your passwords and banking info
A hacker typing quickly on a keyboard
New MassJacker malware is hijacking digital wallets to steal large sums from users
A person trying to set up a new Wi-Fi router
Thousands of TP-Link routers have been infected by a botnet to spread malware
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones