“Apple cannot check ‘[App]’ for malicious software” is a macOS Gatekeeper warning shown when Apple’s normal trust checks cannot be completed for a downloaded app, installer package, or plug-in. On macOS Catalina 10.15 and later, do not override it immediately. First check the official developer site or the App Store for a current signed and notarized copy.

What “Apple Cannot Check [App] for Malicious Software” Means

The app name varies within the warning. You may see Apple cannot check “[App]” for malicious software or the equivalent message “[App]” can’t be opened because Apple cannot check it for malicious software.

This warning can appear when you open an app, installer package, or plug-in downloaded from the internet or directly from a developer. Apple states that macOS Catalina and later require software distributed outside the App Store to be notarized by default. Notarization means Apple has checked submitted software for malicious components.

The alert therefore means that the item is not passing the normal Gatekeeper trust path. Possible documented reasons include software that is not notarized, software that is not signed in a way macOS accepts, an outdated or potentially altered download, or an organization policy that restricts security overrides. The warning does not independently prove that the item contains malware, but it also does not establish that the item is safe.

Apple’s guidance for safely opening Mac apps recommends looking for an updated version, contacting the developer, or obtaining the software from the App Store before creating an exception.

Check the message before continuing: this procedure is limited to the “Apple cannot check” warning. Do not use it if the alert instead says that the developer cannot be verified, the app will damage your computer, or the app is damaged and cannot be opened. Those are different warning states with different safety implications.

First, Get a Trusted Updated or Notarized Copy

When this applies: Use this first whenever you can identify the official developer or vendor responsible for the blocked app, plug-in, or installer.

Prerequisite

  • You can identify the official developer or vendor.

Steps

  1. Check the developer’s official site or the App Store for an updated version.
  2. Prefer a version that is signed and notarized.
  3. If available, compare release notes or checksums from the developer.

Use release notes or a developer-published checksum only as supplemental trust information. A familiar developer, website, or matching checksum does not by itself guarantee that software is safe. Do not replace the file with another copy from an unverified mirror or reposting site.

Expected result: The blocked download is replaced with a current copy obtained through the official developer or the App Store. macOS can then evaluate that replacement through its normal trust process.

Risk: Low. This path does not weaken Gatekeeper or create a security exception.

Rollback: Delete the blocked download and retain or install only the verified replacement. If the replacement cannot be verified, stop rather than overriding the original file.

Contact the Developer or Choose an App Store Alternative

When this applies: Use this path when the current download remains blocked and you need confirmation that the specific file is legitimate.

Prerequisites

  • You know the app name and where the file came from.
  • You can contact the developer or locate an App Store listing.

Steps

  1. Ask the developer whether the build is notarized for macOS Catalina and later.
  2. Request a current notarized build if the file is old.
  3. Use an App Store alternative if one exists.

This applies equally when the blocked item is an installer package or plug-in carrying the same warning. Confirm the specific build rather than assuming that every file distributed under a familiar product name has the same signing or notarization status.

Expected result: You obtain a current notarized build, choose an App Store alternative, or determine that the existing file should not be used.

Risk: Low. No Gatekeeper setting is changed.

Rollback: Stop using the blocked file if the developer cannot confirm it. Do not substitute an unverified mirror download.

Use Open Anyway Only for One Verified Item

Security warning: Unnotarized or unsigned software may expose your Mac and personal information to malware. Use Open Anyway only when you are certain that this specific file is trustworthy and unchanged. Source reputation alone is not proof of safety.

When this applies: Use Apple’s per-item override only after verifying the software and deciding that you trust it. This is the more invasive path because it allows an item that Gatekeeper did not approve through its normal checks.

Prerequisites

  • You already tried to open the item once.
  • You trust the source and have not modified the file.

Steps for current macOS versions

  1. Open System Settings.
  2. Click Privacy & Security.
  3. Scroll down to Security and click Open Anyway.
  4. Confirm the prompt, then click Open.
  5. The app is saved as an exception for future launches.

Apple documents this as an exception for the specific item rather than a global Gatekeeper change. See Apple’s per-item security override instructions for the supported current-interface workflow.

Expected result: If the option is available and macOS accepts the confirmation, the selected item is saved as an exception for future launches. This does not mean Apple has notarized the software or confirmed that it is safe.

Risk: Medium. You are authorizing software that did not pass the normal trust path. Open Anyway may be unavailable on a managed Mac or may be restricted by organization policy.

Rollback: If you no longer trust the software, remove it and do not reopen it. No global Gatekeeper setting needs to be restored because this workflow does not require a broad security change.

Do not remove quarantine metadata with Terminal or disable Gatekeeper globally. Those actions are not part of Apple’s documented general-user resolution for this warning and would bypass the safer per-item process.

Use Security & Privacy on Macs with the Older Interface

When this applies: Use this version-specific path only if the Mac shows System Preferences instead of System Settings. Exact labels can vary across earlier supported macOS releases.

Prerequisite

  • The Mac uses the older System Preferences interface.

Steps

  1. Open System Preferences.
  2. Open Security & Privacy.
  3. Use the supported override path shown by Apple for that version.
  4. Confirm the app only if you trust the source.

Apple’s Mac Help guidance for this warning documents the equivalent warning family and the version-appropriate override concept. Follow the control displayed for your release rather than assuming that current System Settings labels will appear in System Preferences.

Expected result: The verified item receives a version-appropriate per-item exception if the override is available and permitted.

Risk: Medium. The security implications are the same as the current Open Anyway procedure. Organization policy may hide or prevent the override.

Rollback and warning: Do not change broader security settings. If you no longer trust the item, remove it and do not reopen it. Apple does not publish a universal period during which an override remains available in every case, so do not rely on a fixed timeout.