“Apple could not verify this app is free of malware” — what it actually means
This warning means macOS could not confirm an app is free of known malware, which is not the same as finding malware in it. Usually it appears because the developer hasn’t submitted the app to Apple for notarization. Sometimes it appears because the app is genuinely malicious. The dialog can’t tell you which, so the verification has to happen before you click anything, not after.
Key takeaways
- The warning indicates an absence of confirmation rather than a positive malware detection, though it appears for genuinely dangerous software too.
- Gatekeeper checks that an app comes from an identified developer, is notarized by Apple as free of known malicious content, and has not been altered since signing.
- Apple removed the right-click Open shortcut in recent releases; the supported route is now System Settings, Privacy and Security, then Open Anyway.
- Notarization is an automated malware scan, not a review of an app’s quality, privacy practices, or behaviour.
- Disabling Gatekeeper system-wide removes protection from every future install, so approving individual verified apps is the safer equivalent.
What Gatekeeper is actually checking
Apple’s documentation describes the mechanism precisely: when a user opens an app from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered, and it requests user approval before opening downloaded software for the first time.
Three separate checks, and the warning appears if any fails. The most common failure is the second one, since notarization requires a developer to submit the finished app to Apple, which checks it and generates a hash stored in macOS itself; when you download the app, macOS compares its hash against the stored one.
The important nuance for interpreting the warning: notarization requires a paid Apple Developer account. Small developers and open-source projects sometimes don’t have one, which is why perfectly legitimate software triggers the warning. It’s also why the warning alone tells you nothing definitive.
What notarization does not tell you
Worth being clear, because notarized status gets read as an endorsement.
Notarization is an automated scan for known malicious content. It’s not a review of whether an app is well-built, whether it handles your data responsibly, whether the developer is trustworthy, or whether the business model is what it appears to be. An app can be fully notarized and still collect more than you’d like.
Apple’s own framing of the App Store distinguishes the two: App Store apps are reviewed by Apple before acceptance and signed to ensure they haven’t been tampered with, and can be quickly removed if there’s a problem, while software from outside the store gets the Developer ID and notarization checks instead. Different levels of scrutiny, and the gap matters.
Also worth knowing on the privacy question, since it comes up: Apple states that these security checks have never included the user’s Apple Account or device identity, and IP addresses associated with them are not logged.
Verify before you bypass
This is the part most guides skip, and it’s the only part that actually protects you. The bypass steps are trivial. Deciding whether to use them is the real work.
- Where did the download come from? The developer’s own site, or a download aggregator, a mirror, a link in a message, a search ad? Only the first is acceptable. If it wasn’t, delete it and download from the official source.
- Does the developer exist? A real website, a support address that works, a changelog, a privacy policy. An app with no traceable human behind it is exactly the case where the warning should stop you.
- Does anyone else discuss it? Independent mentions on forums, Mac blogs, GitHub, or a Product Hunt listing. Silence around an app that claims users is a signal.
- Does the requested access make sense? A menu bar ticker asking for Full Disk Access or Accessibility permissions is worth questioning. A menu bar manager asking for Screen Recording has a documented reason.
- Are you being rushed? Urgency in the download page, a limited-time framing, or a message pushing you to install now is the strongest single warning sign in this list.
If any of these fail, don’t proceed. The point of the warning is to create a pause, and the pause is only useful if something happens during it.
Opening a verified app on macOS Tahoe
The old advice, right-click the app and choose Open, no longer works. Apple removed that path, so guides still recommending it are out of date.
The current sequence, as documented for Sequoia and Tahoe: the first warning offers Done and Move to Trash; clicking Done dismisses it without enabling the app, and you must then go to System Settings, Privacy and Security, and scroll to the Security section to grant permission.
- Attempt to open the app. The warning appears.
- Click Done, not Move to Trash. This dismisses the dialog and leaves the app in place.
- Open System Settings → Privacy & Security.
- Scroll to Security. A message names the blocked app.
- Click Open Anyway and authenticate with your password or Touch ID.
- Launch the app again. It should open, and it won’t ask again.
This applies per app. Each new blocked app needs its own approval, which is the intended design rather than an inconvenience to route around.
What not to do
| Approach | Why people try it | Why to avoid it |
|---|---|---|
| Disabling Gatekeeper system-wide | Stops all future warnings | Removes the check for every app installed afterwards, including ones you didn’t intend to run |
| Stripping the quarantine attribute via Terminal | Found in forum posts as a quick fix | Bypasses the check without any verification, and copied commands are a known attack vector |
| Approving without checking the source | The app is probably fine | The warning is the only pause you get; skipping the check discards its entire purpose |
| Downloading from an aggregator | Search results rank them highly | Bundled installers and modified builds are a recurring problem in this distribution channel |
Terminal commands circulating for this are worth singling out. Running a command you don’t understand, pasted from a forum, to disable a security feature, is a considerably larger risk than the app you were trying to install.
Gatekeeper is not antivirus
A useful boundary to keep in mind. Gatekeeper, XProtect, and notarization block known threats at install and launch time. Independent security commentary makes the limitation explicit: these protections reduce risk especially for known threats, but malware can still reach users through deceptive downloads, fake software updates, malicious scripts, unsafe browser extensions, phishing, and stolen credentials.
So a notarized app is not audited, and an unnotarized one is not condemned. Both statements are weaker than people read them as.
The same is true for CoinNotch — its notarized status means Apple scanned it, not that it undergoes continuous review.
Where CoinNotch sits on this
CoinNotch is distributed as a notarized Mac app, so under normal circumstances the warning above shouldn’t appear. If it does, the most likely explanation is that the download came from somewhere other than the official site, and the correct response is to delete it and download again from the source rather than clicking through.
Applying the checklist above to this app specifically is reasonable and encouraged. A price ticker needs network access and nothing else. It has no reason to request Full Disk Access, Accessibility, or Screen Recording, and a menu bar app asking for those without a clear explanation deserves the same scepticism regardless of who made it.
Frequently asked questions
Does this warning mean the app has malware?
No. It means macOS could not confirm the app is free of known malware, usually because the developer has not notarized it with Apple. That is an absence of confirmation rather than a detection, though it can also appear for genuinely malicious software.
Why can’t I right-click and choose Open anymore?
Apple removed that shortcut in recent macOS releases. The supported route is now System Settings, then Privacy and Security, where an Open Anyway button appears in the Security section after you dismiss the initial warning.
What is notarization?
Notarization is Apple scanning a developer’s app for known malicious content and issuing a signature if it passes. It is an automated malware check rather than a review of the app’s quality, behaviour, or business practices.
Should I disable Gatekeeper entirely?
No. Disabling it removes the check for every app you install afterwards, including ones you did not intend to run. Approving individual apps you have verified achieves the same result without lowering protection system-wide.
Is an App Store app safer than a notarized one?
App Store apps go through human review and sandboxing requirements in addition to automated scanning, so they carry more scrutiny. Notarized apps outside the store are checked for known malware but not reviewed for behaviour in the same way.
The app says it is damaged and should be moved to Trash. Is that different?
That message usually indicates a signing or quarantine issue rather than actual file corruption, and often appears with incorrectly signed downloads. Re-downloading from the official source is the first thing to try before anything more involved.
The habit worth keeping
Download from the developer’s site. Read the warning rather than dismissing it reflexively. Approve individual apps you’ve checked rather than turning the system off. That’s most of macOS security hygiene for third-party software, and it costs about thirty seconds per install.
The same scepticism applies to what you keep installed over time, since an app you approved two years ago and stopped using is still running. That audit pairs naturally with our guide to the best menu bar apps for Mac, which covers what earns permanent space and what doesn’t.
This article is for information only. It is not financial, investment, or tax advice. Crypto assets are volatile and you can lose everything you put in. CoinNotch displays public market data and does not trade, hold funds, or connect to any account.