This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ZWDeJun/ZWDeJun
- https://github.com/d-rn/vulBox
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/jhftss/POC