apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26

New Mac malware steals passwords via crash reports

Milan Jovicic by Milan Jovicic
July 15, 2026 - 3:22 PM CEST
in Apple News
0
Mac crash reports Passwords

Image: Shutterstock / AIBooth

WhatsAppFacebookEmail
Threads

When an app crashes, macOS offers to send an error report to Apple – a familiar process. A new piece of malware mimics this process: it requests the Mac password and then accesses the keychain, password manager, and cryptocurrency wallets. This trick only works with the help of a tool that is currently barely noticeable.

macOS is considered stable, but every now and then an app crashes, and the system offers to send a diagnostic report. The security firm Jamf Threat Labs has discovered malware that spoofs this process and steals the login password. Anyone who enters it grants the software access to a large portion of their personal data. This tactic demonstrates once again that a Mac is not a free pass against attacks – how to protect Apple devices from malware in general remains a fundamental question of personal security.

This is how the attack unfolds

The malware is known as CrashStealer by Jamf. Initial contact is not random, but occurs via a disguised meeting app called "Werkbit," which is distributed as supposed video conferencing software. The download is protected with a meeting PIN – an indication that the attackers are sending the file to targeted victims, for example via fake invitations to alleged job interviews, rather than distributing it widely.

An automated infection does not occur. The victim must download and launch the app and then enter their Mac password. Only then does the software install a second component in the background, masquerading as Apple's crash reporting tool – complete with a fitting name, icon, and the internal identifier com.apple.crashreporter. A password dialog, styled like macOS, appears on the screen, with accompanying text that disguises the extensive system access as purely maintenance-related.

What the software collects

The malware first checks the entered password locally using a built-in macOS tool. If it's correct, it unlocks the login keychain and copies it to a hidden folder. From there, access expands to browser data such as saved logins and cookies, to approximately 14 password managers – including 1Password, Bitwarden, LastPass, Dashlane, and Keeper – and to about 80 crypto wallets such as MetaMask, Phantom, and Coinbase. It also scans the "Documents" and "Downloads" folders for usable files.

CrashStealer encrypts the collected data directly on the device before it is sent to an external server. The software also embeds itself in such a way that it restarts every time the user logs in. Jamf also discovered Windows versions of the same campaign – meaning the attackers are targeting multiple platforms, not just Macs.

Why Gatekeeper didn't initially trigger

Particularly concerning is the method the attackers used to circumvent macOS's security mechanisms. The "Werkbit" app was signed with a valid Apple developer ID and notarized by Apple – even the disk image itself bore a signature, which is unusual for malware. As a result, the file passed the Gatekeeper check on its first launch without any warning.

After Jamf reported the discovery, Apple revoked the misused developer credentials. The known variant should now be detected and blocked by Gatekeeper. This mitigates the specific case, but doesn't negate the underlying lesson: A valid Apple signature alone is not proof of trustworthiness.

This is how the attack can be repelled

A simple warning sign can help in everyday life: Apple's genuine crash reporting tools are already part of macOS. A file called CrashReporter.dmg, which is offered for download, is not one of them and should raise suspicion. It's also worth taking a second look at any password dialog that requires extensive system changes – especially if it appears in connection with a newly installed app.

The most reliable protection remains downloading programs only from the Mac App Store or from the websites of trusted developers, and critically examining invitations to unknown meeting apps. Since the attack targets the entered password, consistently active two-factor authentication for your Apple account is also helpful: even stolen login credentials are then significantly less valuable to an attacker. Those who want to avoid using a reusable password altogether can use Passkeys on Apple devices, a method that cannot be intercepted via a fake dialog box.

Signed software is not a license to do free speech

CrashStealer is not a mass attack, but a targeted, elaborately constructed campaign – and that's precisely what makes it such a textbook example. The attackers obtained a genuine developer ID, had their malware notarized, and narrowed the crucial moment down to a single user action: entering the password in a deceptively realistic dialog box. Anyone who pauses at this point undermines the entire scheme. (Image: Shutterstock / AIBooth)

  • Nine new emojis are planned: Pickle, Lighthouse and Meteor
  • China releases Apple Intelligence – with Qwen and Baidu
  • OpenAI sees no evidence to support Apple's theft claim
  • Apple Watch exempt from the EU battery replacement requirement
  • Apple grows by 24 percent in China against the market trend
  • Apple TV shows the trailer for "Mayday" starring Ryan Reynolds
  • Madden NFL 27 launches on August 6th on Apple Arcade
  • Apple rejects Epic's objections to the procedural pause
  • WhatsApp is working on a backup alternative to iCloud
  • iOS 26.6 warns of harmful messages
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: CybersecuritymacOS
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Nine new emojis are planned: Pickle, Lighthouse and Meteor

Next Post

An email glitch caused talks between Apple and OpenAI to fail

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Related posts

watchOS 27.2: Code reveals new screenshot preview

by Milan Jovicic
September 24, 2026 - 8:36 p.m. CEST
Apple Watch Ultra with an orange band showing the app view, the device getting the new screenshot preview in watchOS 27.2

watchOS 27.2 includes a new screenshot interface for the Apple Watch: preview, share, and delete, just like on the iPhone. It's currently inactive.

Read moreDetails

Apple TV: Peanuts classics free again for Christmas

by Milan Jovicic
September 24, 2026 - 6:43 p.m. CEST
Charlie Brown holding a small Christmas tree under a starry sky in the snow, a scene from A Charlie Brown Christmas, free again on Apple TV

Three classic Peanuts cartoons are back on Apple TV for the holidays, no subscription required. Plus, there are new specials featuring Snoopy and the Fraggle Rocks.

Read moreDetails

The Wanted Man: Hugh Laurie on Apple TV from January

by Milan Jovicic
September 24, 2026 - 6:19 p.m. CEST
Hugh Laurie as crime boss Felix Carmichael in an evening scene from The Wanted Man on Apple TV

The Wanted Man premieres on January 6, 2027 on Apple TV. Hugh Laurie plays a crime boss who wants to escape – the finale is in February.

Read moreDetails

Apple and Qualcomm extend patent license from 2027

by Milan Jovicic
September 24, 2026 - 6:04 p.m. CEST
Back of an iPhone 18 Pro Max in a burgundy case on a grey surface, covered by the renewed Apple Qualcomm patent license

Apple and Qualcomm are extending their patent license from April 2027. Why this has nothing to do with the modem change and affects Germany.

Read moreDetails

iPhone 18 Pro: Update to prevent Face ID restarts is coming

by Milan Jovicic
September 24, 2026 - 1:13 p.m. CEST
iPhone showing the General settings with Software Update, where the fix for the Face ID reboots on iPhone 18 Pro will arrive

Apple has confirmed an update to fix the restarts after failed Face ID recognition on the iPhone 18 Pro and Pro Max. An exchange is not worthwhile.

Read moreDetails
Load More

Categories

  • Apple Insights
  • Apple Rumors
  • Apple News
  • Apple Tips & Tricks
  • iPhone news, rumors and tips
  • Mac and MacBook News
  • Reviews

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch