	{"id":49252,"date":"2016-01-15T11:48:06","date_gmt":"2016-01-15T19:48:06","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=49252"},"modified":"2016-01-15T11:48:06","modified_gmt":"2016-01-15T19:48:06","slug":"apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/","title":{"rendered":"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-49255\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-600x300.jpeg\" alt=\"Ghoul Gate\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-600x300.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-600x300-150x75.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-600x300-300x150.jpeg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Anyone who remembers those &#8220;I&#8217;m a PC, I&#8217;m a Mac&#8221; ads from some years back will surely remember that a key message that Apple wants to get across to potential customers was this: PCs have a malware problem, Macs don&#8217;t.<\/p>\n<p>Of course, that message was partly spin \u2014 there had been malware for Apple computers, even before it had existed for PCs.<\/p>\n<p>And, in recent years, although the vast majority of malicious code is written for Windows and Android rather than OS X, there have been outbreaks and most Mac owners realise today the importance of protecting their precious computers from attack.<\/p>\n<p>Apple, naturally, wants to reduce the chances of malware becoming a widespread problem on OS X \u2014 and one of the ways it has tried to deal with that is by incorporating Gatekeeper into the operating system, a means to stop unverified, unsigned apps from making their way onto your iMacs and MacBooks.<\/p>\n<p>But, as we reported last October, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/researcher-demonstrates-how-malware-can-bypass-os-xs-completely-broken-gatekeeper\/\" target=\"_blank\">serious security holes<\/a> have been found in Gatekeeper that\u00a0could allow malware to completely bypass Gatekeeper&#8217;s checks.<\/p>\n<p>Patrick Wardle, the researcher who uncovered that vulnerability (known as CVE-2015-7024), claims that despite twice attempting to permanently fix the security flaw, Apple&#8217;s solution continues to contain cracks that could allow a malicious hacker to wreak havoc on Apple computers.<\/p>\n<p>The slides in Wardle&#8217;s presentation make clear that he doesn&#8217;t have the highest opinion of OS X&#8217;s built-in security.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-49258\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/gatekeeper-slide.jpeg\" alt=\"gatekeeper presentation slide from Patrick Wardle\" width=\"600\" height=\"319\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/gatekeeper-slide.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/gatekeeper-slide-150x80.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/gatekeeper-slide-300x160.jpeg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Generally, in my opinion, Gatekeeper does a reasonable job.<\/p>\n<p>If an app is developed by an unknown developer, or has been tampered with en route to your computer via a man-in-the-middle attack over an unencrypted HTTP connection, then Gatekeeper is supposed to spot it and block it.<\/p>\n<p>But, as <a href=\"https:\/\/www.intego.com\/mac-security-blog\/researcher-demonstrates-how-malware-can-bypass-os-xs-completely-broken-gatekeeper\/\" target=\"_blank\">Wardle showed last year<\/a> at the Virus Bulletin conference in Prague, there exists a way to waltz past Gatekeeper even if you had configured your Mac to use the maximum &#8220;App Store-only&#8221; security setting.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-46753\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/10\/security-setting.jpeg\" alt=\"OS X security setting\" width=\"600\" height=\"201\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/10\/security-setting.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/10\/security-setting-150x50.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/10\/security-setting-300x101.jpeg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>The trick Wardle used was to use a legitimate app that already successful passes Apple&#8217;s Gatekeeper check, but that loads or runs code from the same folder, and bundling both into a disk image.<\/p>\n<p>As the legitimate app has already been digitally-signed, Gatekeeper failed to check other content in the disk image that may have a malicious impact.<\/p>\n<p>Clearly this was a problem that had to be fixed \u2014 and Apple issued patches to address the issue last October, and again last week.<\/p>\n<p>The problem appears to be that Apple&#8217;s fixes have been targeted specifically at the proof-of-concept exploits that Wardle has shared with the engineers in Cupertino, blacklisting particular binaries rather than creating a more comprehensive solution to the issue.<\/p>\n<p>As a result, Wardle <a title=\"LInk to engadget article\" href=\"http:\/\/www.engadget.com\/2016\/01\/15\/apples-gatekeeper-vulnerability-still-needs-to-be-fixed\/\" target=\"_blank\" rel=\"nofollow\">claims<\/a> he has been able to bypass Gatekeeper&#8217;s protection \u2014 even with the patches in place \u2014 within minutes.<\/p>\n<p>The researcher says he will present his full findings at the Shmoocon security conference in Washington DC today, and will release a tool to help plug the gaps that Apple has continued to leave open.<\/p>\n<p>Let&#8217;s hope that Apple can learn something from Wardle&#8217;s research, and build their own comprehensive fix, that will benefit all of us who rely on computers running Mac OS X.<\/p>\n<p><span style=\"font-size: x-small;\">photo credit: <a title=\"The Ghoul-Gate\" href=\"http:\/\/flickr.com\/photos\/micadew\/6552626577\">flickr photo<\/a> shared by <a href=\"http:\/\/flickr.com\/people\/micadew\">micadew<\/a> under a <a href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/2.0\/\">Creative Commons ( BY-SA ) license<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.<\/p>\n","protected":false},"author":34,"featured_media":49261,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,13],"tags":[2641,2500,168,2161,144],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2016-01-15T19:48:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Graham Cluley\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg\",\"width\":400,\"height\":260},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/\",\"name\":\"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage\"},\"datePublished\":\"2016-01-15T19:48:06+00:00\",\"dateModified\":\"2016-01-15T19:48:06+00:00\",\"description\":\"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/4bb722788ecdbd86fde47a5cf256bde2\"},\"headline\":\"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher\",\"datePublished\":\"2016-01-15T19:48:06+00:00\",\"dateModified\":\"2016-01-15T19:48:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage\"},\"wordCount\":548,\"commentCount\":2,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg\",\"keywords\":[\"CVE-2015-7024\",\"Gatekeeper\",\"OS X\",\"Patrick Wardle\",\"Vulnerability\"],\"articleSection\":[\"Apple\",\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/4bb722788ecdbd86fde47a5cf256bde2\",\"name\":\"Graham Cluley\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/aa9ea0686c5d1aa9086d4b12c3aa05f2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/aa9ea0686c5d1aa9086d4b12c3aa05f2?s=96&d=mm&r=g\",\"caption\":\"Graham Cluley\"},\"description\":\"Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by companies such as Sophos, McAfee and Dr Solomon's. He has given talks about computer security for some of the world's largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats. Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the \\\"10 Greatest Britons in IT History\\\" for his contribution as a leading authority in internet security. Follow him on Twitter at @gcluley.\",\"sameAs\":[\"https:\/\/grahamcluley.com\/\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/","og_locale":"en_US","og_type":"article","og_title":"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher - The Mac Security Blog","og_description":"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/","og_site_name":"The Mac Security Blog","article_published_time":"2016-01-15T19:48:06+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Graham Cluley","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg","width":400,"height":260},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/","name":"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage"},"datePublished":"2016-01-15T19:48:06+00:00","dateModified":"2016-01-15T19:48:06+00:00","description":"Despite two attempts, Apple appears to have failed to properly fix OS X against a serious security issue that could help hackers install malicious code.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/4bb722788ecdbd86fde47a5cf256bde2"},"headline":"Apple Fails to Properly Fix Gatekeeper Security Hole, Claims Researcher","datePublished":"2016-01-15T19:48:06+00:00","dateModified":"2016-01-15T19:48:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#webpage"},"wordCount":548,"commentCount":2,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg","keywords":["CVE-2015-7024","Gatekeeper","OS X","Patrick Wardle","Vulnerability"],"articleSection":["Apple","Security &amp; Privacy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-fails-to-properly-fix-gatekeeper-security-hole-claims-researcher\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/4bb722788ecdbd86fde47a5cf256bde2","name":"Graham Cluley","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/aa9ea0686c5d1aa9086d4b12c3aa05f2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/aa9ea0686c5d1aa9086d4b12c3aa05f2?s=96&d=mm&r=g","caption":"Graham Cluley"},"description":"Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by companies such as Sophos, McAfee and Dr Solomon's. He has given talks about computer security for some of the world's largest companies, worked with law enforcement agencies on investigations into hacking groups, and regularly appears on TV and radio explaining computer security threats. Graham Cluley was inducted into the InfoSecurity Europe Hall of Fame in 2011, and was given an honorary mention in the \"10 Greatest Britons in IT History\" for his contribution as a leading authority in internet security. Follow him on Twitter at @gcluley.","sameAs":["https:\/\/grahamcluley.com\/"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/01\/broken-gate-400x260.jpeg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-cOo","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/49252"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=49252"}],"version-history":[{"count":9,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/49252\/revisions"}],"predecessor-version":[{"id":49273,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/49252\/revisions\/49273"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/49261"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=49252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=49252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=49252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}