Free tools Windows power users keep installed
One-click scans. No signup required.
In 2021, F-Secure engineer Rasmus Sten released proof-of-concept code for CVE-2021-1810, a macOS Gatekeeper bypass affecting historical versions of Catalina and Big Sur. The bug was in Archive Utility: extracting a specially crafted ZIP with very long paths could leave extracted files without the com.apple.quarantine attribute that Gatekeeper relies on. Apple fixed the issue in macOS Big Sur 11.3 and Security Update 2021-002 for Catalina.
The exploit required a victim to download and open the archive. It was not described as a zero-click or purely remote attack, and the 2021 report does not establish compatibility with current macOS releases.
What CVE-2021-1810 did
Gatekeeper checks software downloaded from the internet before allowing it to run. macOS commonly records that download history in the com.apple.quarantine extended attribute. SecurityWeek reported that Archive Utility could fail to apply this metadata when extracting paths longer than 886 characters. That figure is the threshold reported in the 2021 account, not an independently established universal limit for every system or archive.
Without the quarantine metadata, an extracted unsigned application could avoid the normal Gatekeeper warning. Apple’s Big Sur 11.3 security advisory describes the impact as a malicious application bypassing Gatekeeper checks and credits Sten as the reporting researcher. Apple characterized the fix as improved state management.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How the proof of concept worked
- Craft the archive: The ZIP used deeply nested folders to create unusually long paths.
- Make it look ordinary: The reported proof of concept used a symbolic link and a hidden, dot-prefixed folder structure so the archive could resemble a single application bundle at its root. Sten explained that the layout was intended to be “almost indistinguishable from a single app bundle in the archive root.”
- Get the archive opened: An attacker had to persuade a user to download and open the ZIP.
- Run the extracted application: If the relevant quarantine metadata was missing, the unsigned binary could execute without the expected Gatekeeper alert.
This sequence makes user interaction a required part of the reported attack. The available account does not describe a drive-by compromise, a zero-click exploit, or an attack that worked merely because a Mac was connected to the internet.
Which macOS versions were affected?
The historical reports identify Catalina and Big Sur as affected product lines. Apple and the National Vulnerability Database record the following remediation points:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| macOS line | Historical fix | What the record establishes |
|---|---|---|
| macOS Big Sur | macOS Big Sur 11.3 | Apple’s security advisory documents CVE-2021-1810 and the fix. |
| macOS Catalina | Security Update 2021-002 | The update history identifies this release as fixing the issue. |
| Other or current macOS releases | Not established by the 2021 PoC report | The available reporting does not prove that the PoC works on present-day macOS. |
For a Mac still running an older system, install the latest security updates Apple offers for that device. The practical historical minimums for this CVE were Big Sur 11.3 and Catalina Security Update 2021-002; later updates supersede them.
What users should do now
Check for updates
- Open the Apple menu and choose System Settings (or System Preferences on older macOS).
- Open General > Software Update in newer macOS, or select Software Update in System Preferences on older releases.
- Install every security update offered for the Mac, then restart if requested.
Do not treat the existence of the 2021 PoC as proof that an updated Mac is currently vulnerable. The source material establishes the affected historical releases and their fixes, but does not establish present-day exploitability.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Handle downloaded archives cautiously
- Do not open ZIP files from unsolicited messages, advertisements, or untrusted download pages.
- Verify the publisher before launching an extracted application, especially if macOS displays an unidentified-developer or damaged-app warning.
- Keep automatic macOS security updates enabled where supported.
Do not confuse this CVE with CVE-2021-30657
Apple’s Catalina Security Update 2021-002 advisory lists CVE-2021-30657 as a separate Gatekeeper bypass and notes a report of possible active exploitation for that issue. That statement does not describe CVE-2021-1810 or Sten’s ZIP/Archive Utility proof of concept. Both appeared in the same period, which is why accounts of 2021 Gatekeeper problems can be conflated, but their CVE details and reporting context must remain separate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How later Gatekeeper behavior fits in
Apple Developer wrote in August 2024 that macOS Sequoia would no longer let users Control-click to override Gatekeeper for software that was not correctly signed or notarized. Instead, users would review the security information in System Settings > Privacy & Security before allowing it to run. That is a later protection-behavior change, not the fix for CVE-2021-1810, and it does not show that the 2021 PoC affects Sequoia.
Quick Recap
Best Value
- FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
- Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
- Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
- USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
- Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What is and is not known about the incident
- Known: Sten released proof-of-concept code; the reported weakness involved Archive Utility, long extraction paths, missing quarantine metadata, and a crafted ZIP.
- Known: The user had to download and open the archive for the reported chain to proceed.
- Known: Apple fixed the vulnerability in Big Sur 11.3 and Catalina Security Update 2021-002.
- Not established: A population-wide count of vulnerable Macs, exploitation frequency, or compatibility with current macOS releases.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

