Malware · guide

Apple could not verify is free of malware, and what that means

By Alberto Gulotta · Updated · 15 min read

Apple could not verify is free of malware means the app was never checked, not that anything was found in it: it has not been notarised. macOS uses a different message when it does detect something. Before overriding, Apple’s own guide calls that override the commonest way a Mac gets infected.

Two different macOS alerts, and only one of them means malware was found The alert people search for says macOS cannot verify that the app is free of malware, which Apple explains as the app not having been notarised. When macOS actually detects malicious content it shows a different alert saying the app will damage your computer, and known malware is moved to the Trash. THE MESSAGE YOU GOT, AND THE MESSAGE YOU DID NOT GET macOS “can’t verify that the app is free of malware” Apple: the app “hasn’t been notarized by Apple” nothing was found, because nothing was checked “Will damage your computer” Apple: macOS “detects that software has malicious content” and for known malware the app is moved to the Trash They are two of the five alerts Apple documents on one page. Reading the first as the second is what makes people delete software that was fine — and reading it as nothing is the costlier mistake. AI Tools Primer · figure
The distinction is on Apple’s own support page, and it is the part the short answers leave out. Figure drawn by AI Tools Primer.

What the message actually says, which is not what it sounds like

Read literally, a message saying Apple could not verify that an app is free of malware sounds like a failed inspection. It is the opposite: there was no inspection. Apple’s own wording for this alert is precise about why — if the app developer cannot be verified and “the app hasn’t been notarized by Apple, macOS can’t verify that the app is free of malware”.

Notarisation is the missing step. Apple describes what it means when it has happened: “an app that has been notarized by Apple indicates that Apple checked it for malicious software and none was detected”. A developer submits the app, Apple scans it, and a ticket is attached. Software that skips that process is not suspect; it is unexamined. The most common reasons are ordinary: a small developer without a paid Apple Developer account, an open-source tool, an old build made before notarisation was required, or a file that lost its signature in transit.

The proof that this alert is not a detection is that macOS has a different alert for detection, on the same Apple page. “If macOS detects that software has malicious content or its authorization has been revoked for any reason, your Mac notifies you that the app will damage your computer.” And when it recognises something specific: “if macOS detects known malware, your Mac notifies you that the app can’t be opened and moves it to the Trash”.

So the sentence to keep is short. “Cannot verify” means not checked. “Will damage your computer” means checked, and bad. If you saw the first one, macOS has not found anything in your file.

The five alerts macOS shows when opening an app, what each one means, and which of them is the one people search for. Quoted from Apple’s “Safely open apps on your Mac”, updated 27 May 2026 and read on 9 September 2026.
The alertWhat macOS is telling youWas malware found?
Downloaded from the internet First time opening an app from an identified developer, from outside the App Store. No. It is a first-run confirmation.
Developer cannot be verified — “can’t verify that the app is free of malware” The app is not notarised, so it was never checked. No. It was not looked at.
Apple cannot check the app for malicious software Same underlying situation, worded for the check rather than the developer. No.
Not downloaded from the App Store Your settings allow App Store apps only. No. It is your own setting.
“Will damage your computer”, or the app is damaged macOS detected malicious content, or a revoked authorisation. Yes — and known malware is moved to the Trash.

And the sentence that should come before the click

Every guide to this message ends with the same three steps, and so does this one. What almost none of them includes is what Apple writes immediately above those steps, in its Mac User Guide:

“Overriding security settings to open an app is the most common way that a Mac gets infected with malware. You should not override security settings if an app hasn’t been checked by Apple, even if the app looks like it comes from a major developer.”

That is not a disclaimer, it is a finding, and the clause at the end is the working part. “Even if the app looks like it comes from a major developer” describes exactly the situation in which people override: the download claimed to be a familiar name, so the warning felt like bureaucracy. Looking right is the attack, not the reassurance.

Apple’s recommended order puts the override third rather than first: “the safest approach is to look for a version of the app from the Mac App Store or look for an alternative app”, and only then, “if you choose”, the manual override. Two questions settle it in practice. Did you go to the developer’s own site and start the download yourself, or did the file arrive — in an email, a message, a link from a search result? And is the app well known enough that an unsigned build would be strange? A large company that ships Mac software notarises it; an unsigned installer bearing a large company’s name is the case Apple is warning about by name.

If you are certain, this is the sequence — and its two catches

Try to open the app first and let it be refused; the override only appears afterwards. Then: open System Settings, click Privacy & Security, scroll down to Security, and click Open Anyway. The warning reappears, and clicking Open confirms it. On current versions you enter your login password to finish.

The first catch explains why the button is often missing. Apple states it plainly: “this button is available for about an hour after you try to open the app”. People who read a guide, come back later and find nothing in Privacy & Security are not looking in the wrong place — the window has closed. Open the app again to be refused again, and the button returns.

The second catch is that the decision is permanent. Apple: the app “is now saved as an exception to your security settings, and you can open it in the future by double-clicking it, just as you can any authorized app”. There is no expiry and no reminder. You are not opening the file once; you are adding it to the list of things this Mac trusts.

One setting sits above all of this, under Privacy & Security, Security, “Allow apps downloaded from”: App Store, or App Store and identified developers. If your Mac only offers the stricter option, or offers neither, Apple gives the reason: “these settings might not be available if your Mac is managed by a system administrator or IT department”. On a work Mac that is the answer, and the right next step is to ask them rather than to look for a way around it.

The decision to make before clicking Open Anyway Apple’s recommended order: look for the app in the Mac App Store, or look for an alternative app. Only if you are certain of the source should you override, and Apple states that overriding is the most common way a Mac gets infected. The Open Anyway button is available for about an hour after the failed attempt, and the app is then saved as a permanent exception. APPLE’S OWN ORDER, NOT A LIST OF FIXES 1. Look in the App Store “the safest approach is to look for a version of the app” there 2. Or find an alternative Apple offers this as an equal option, not as a consolation 3. Only then, override and only “if you’re certain” of the source The button with a clock on it “available for about an hour after you try to open the app” And it does not expire the app is “saved as an exception to your security settings” from then on Two facts that decide the click, both on Apple’s pages, neither in the summary above the results. AI Tools Primer · figure
The hour explains why the button seems to vanish; the exception explains why the decision is permanent. Figure drawn by AI Tools Primer.

Three files, three answers

The same alert, and why the right decision is not the same one each time.

A PDF, an image or a document This alert is about apps and installer packages, so a plain document should not normally produce it. If a file you thought was a document triggers an app alert, that mismatch is itself the finding: check what the file actually is before opening it.
A small or open-source tool you went looking for The ordinary honest case: for a small developer, unsigned often means unpaid rather than unsafe. Apple’s order still applies: check the App Store or an alternative first, and if you override, do it knowing the exception is permanent.
An installer bearing a well-known company’s name The case Apple singles out. Large developers notarise their Mac software, so an unsigned build carrying a big name is the specific situation behind “even if the app looks like it comes from a major developer”. Download it again from the maker’s own site and see whether the alert appears at all.

Why the answers to this question are nearly always just clicks. Both of the pages this one draws on are Apple’s own, and neither is hard to find. What gets repeated is the three-step override, because that is what someone stuck in front of a dialogue box asks for. What gets dropped is the sentence that decides whether to take those steps at all, and the fact that the message never claimed to have found anything. An answer that hands you the click and omits both is answering a shorter question than the one that was asked.

If the alert was the other one. A Mac that says an app “will damage your computer” has detected something, and that is a different job: removing malware from a computer covers the sequence and what a clean scan does not settle. If the warning arrived in a browser window rather than from macOS, it is not from your Mac at all — that kind of security alert is a web page, whichever operating system it names.

Where to start

Three ways in.

“Do I have a virus?”
What the message says — what it means
“Should I open it anyway?”
Apple’s own warning — the warning
“Where is the button?”
The hour, and the exception — how to open

When something really was found

This page is about a message that reports no detection. These are for when there is one.

The same question on other devices

What each system will and will not let you install is the difference between these guides.

Questions people also ask

What does Apple could not verify is free of malware mean?

That the app was not notarised, so Apple never examined it. Apple’s wording is that if the developer cannot be verified and the app “hasn’t been notarized by Apple, macOS can’t verify that the app is free of malware”. Nothing was found because nothing was checked.

Does this message mean the app has a virus?

No. macOS uses a different alert when it detects something: it says the app “will damage your computer”, and for known malware it refuses to open the app and moves it to the Trash. If you saw the “cannot verify” wording, no detection happened.

How do I open an app macOS will not let me open?

Try to open it and let it be refused, then open System Settings, click Privacy & Security, scroll to Security and click Open Anyway, confirm at the second prompt and enter your login password. Apple advises checking the App Store or an alternative app first.

Why is there no Open Anyway button in Privacy & Security?

Because the window has passed. Apple states the button “is available for about an hour after you try to open the app”. Open the app again so it is refused again, then go straight to Privacy & Security and the button will be there.

Is it safe to click Open Anyway?

Apple’s own answer is a warning: “overriding security settings to open an app is the most common way that a Mac gets infected with malware”, and you should not do it for an unchecked app “even if the app looks like it comes from a major developer”.

Can I undo it after clicking Open Anyway?

The permission does not expire on its own. Apple states the app is “saved as an exception to your security settings” and opens normally from then on, so the way back is to remove the app itself rather than to withdraw the approval.

Not covered here. It does not tell you whether your particular file is safe, and no page can. What it does is separate what macOS actually said from what it is usually read as saying, so the decision is yours on the real information.

It does not cover the command line methods for stripping the quarantine attribute. Those bypass the check rather than answer it, and the point of this page is the check.

And it does not cover a managed Mac, where the setting may be absent by policy. Apple says so directly, and the answer there is the administrator rather than a workaround. What holds instead is simple: the difference between the two alerts is quoted from Apple’s own support page, the warning about overriding is quoted in full from Apple’s Mac User Guide rather than summarised, the one-hour window and the permanent exception are Apple’s own words, and the page says plainly that no page can tell you whether your particular file is safe.

Sources

  1. Apple Support — Safely open apps on your Mac, updated 27 May 2026: the five alerts macOS can display and what each means, including that an unverified developer and an app that has not been notarised is why “macOS can’t verify that the app is free of malware”; that a notarised app “indicates that Apple checked it for malicious software and none was detected”; the separate alerts for software with malicious content and for known malware moved to the Trash; the override steps; the two “Allow apps downloaded from” settings and that they may be unavailable on a managed Mac — support.apple.com, read 9 September 2026.
  2. Apple Mac User Guide — Apple can’t check app for malicious software: the statement that overriding security settings is the most common way a Mac gets infected with malware and that you should not do it even if the app looks like it comes from a major developer; the advice to look for the app in the Mac App Store or for an alternative first; and the override steps including that the Open Anyway button is available for about an hour after the attempt and that the app is then saved as an exception — support.apple.com, read 9 September 2026.
  3. National Cyber Security Centre — Antivirus and other security software, Device security guidance: the reasoning that a device which can only run software delivered through a monitored store gains very limited value from antivirus, which is the same argument that macOS’s notarisation check is built on — www.ncsc.gov.uk, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.