New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password

A newly discovered macOS malware, dubbed ClickLock, is wreaking havoc on unsuspecting users by repeatedly killing their apps every 210 milliseconds until they enter their password. This malicious program exploits a vulnerability in macOS’s permission system, allowing it to bypass security checks and gain unauthorized access to sensitive data.

ClickLock works by exploiting a weakness in the way macOS handles permissions for user-owned applications. When an app is launched, the operating system checks its permissions to determine what actions it can perform on the system. However, ClickLock has found a way to manipulate this process, allowing it to repeatedly kill the target application and force the user to re-enter their password every 210 milliseconds. This constant barrage of prompts is designed to exhaust the user’s patience, eventually leading them to enter their credentials in desperation.

The malware affects any macOS user who has installed an infected app from a third-party store or downloaded it from a malicious website. ClickLock can be spread through various means, including drive-by downloads, phishing attacks, and exploited vulnerabilities in other software. Once installed, the malware can access sensitive data such as login credentials, financial information, and personal identifiable details.

The impact of ClickLock is not limited to individual users; organizations that use macOS-based systems are also at risk. If an infected app is used within a corporate network, it could potentially compromise sensitive business data and expose the organization to various threats. Furthermore, the fact that ClickLock exploits a vulnerability in macOS’s permission system raises concerns about the overall security of Apple’s operating system.

The emergence of ClickLock serves as a reminder that even the most advanced security systems can be vulnerable to attacks. As AI-powered threat detection tools become more prevalent, attackers are finding new ways to exploit software vulnerabilities and evade traditional security measures. To mitigate this risk, users should remain vigilant when downloading apps from third-party stores or websites, and ensure their operating system is up-to-date with the latest security patches.

To protect yourself against malware like ClickLock, it’s essential to maintain good cybersecurity habits. Always download apps from reputable sources, be cautious of email attachments and links, and keep your operating system and software updated with the latest security patches. Additionally, consider using a reputable anti-malware solution to detect and remove any potential threats. By staying informed and taking proactive steps to secure your digital environment, you can minimize the risk of falling victim to sophisticated attacks like ClickLock.


Source: The Hacker News — 2026-07-16