Malware · guide
Apple could not verify is free of malware, and what that means
By Alberto Gulotta · Updated · 15 min read
Apple could not verify is free of malware means the app was never checked, not that anything was found in it: it has not been notarised. macOS uses a different message when it does detect something. Before overriding, Apple’s own guide calls that override the commonest way a Mac gets infected.
What the message actually says, which is not what it sounds like
Read literally, a message saying Apple could not verify that an app is free of malware sounds like a failed inspection. It is the opposite: there was no inspection. Apple’s own wording for this alert is precise about why — if the app developer cannot be verified and “the app hasn’t been notarized by Apple, macOS can’t verify that the app is free of malware”.
Notarisation is the missing step. Apple describes what it means when it has happened: “an app that has been notarized by Apple indicates that Apple checked it for malicious software and none was detected”. A developer submits the app, Apple scans it, and a ticket is attached. Software that skips that process is not suspect; it is unexamined. The most common reasons are ordinary: a small developer without a paid Apple Developer account, an open-source tool, an old build made before notarisation was required, or a file that lost its signature in transit.
The proof that this alert is not a detection is that macOS has a different alert for detection, on the same Apple page. “If macOS detects that software has malicious content or its authorization has been revoked for any reason, your Mac notifies you that the app will damage your computer.” And when it recognises something specific: “if macOS detects known malware, your Mac notifies you that the app can’t be opened and moves it to the Trash”.
So the sentence to keep is short. “Cannot verify” means not checked. “Will damage your computer” means checked, and bad. If you saw the first one, macOS has not found anything in your file.
| The alert | What macOS is telling you | Was malware found? |
|---|---|---|
| Downloaded from the internet | First time opening an app from an identified developer, from outside the App Store. | No. It is a first-run confirmation. |
| Developer cannot be verified — “can’t verify that the app is free of malware” | The app is not notarised, so it was never checked. | No. It was not looked at. |
| Apple cannot check the app for malicious software | Same underlying situation, worded for the check rather than the developer. | No. |
| Not downloaded from the App Store | Your settings allow App Store apps only. | No. It is your own setting. |
| “Will damage your computer”, or the app is damaged | macOS detected malicious content, or a revoked authorisation. | Yes — and known malware is moved to the Trash. |
And the sentence that should come before the click
Every guide to this message ends with the same three steps, and so does this one. What almost none of them includes is what Apple writes immediately above those steps, in its Mac User Guide:
“Overriding security settings to open an app is the most common way that a Mac gets infected with malware. You should not override security settings if an app hasn’t been checked by Apple, even if the app looks like it comes from a major developer.”
That is not a disclaimer, it is a finding, and the clause at the end is the working part. “Even if the app looks like it comes from a major developer” describes exactly the situation in which people override: the download claimed to be a familiar name, so the warning felt like bureaucracy. Looking right is the attack, not the reassurance.
Apple’s recommended order puts the override third rather than first: “the safest approach is to look for a version of the app from the Mac App Store or look for an alternative app”, and only then, “if you choose”, the manual override. Two questions settle it in practice. Did you go to the developer’s own site and start the download yourself, or did the file arrive — in an email, a message, a link from a search result? And is the app well known enough that an unsigned build would be strange? A large company that ships Mac software notarises it; an unsigned installer bearing a large company’s name is the case Apple is warning about by name.
If you are certain, this is the sequence — and its two catches
Try to open the app first and let it be refused; the override only appears afterwards. Then: open System Settings, click Privacy & Security, scroll down to Security, and click Open Anyway. The warning reappears, and clicking Open confirms it. On current versions you enter your login password to finish.
The first catch explains why the button is often missing. Apple states it plainly: “this button is available for about an hour after you try to open the app”. People who read a guide, come back later and find nothing in Privacy & Security are not looking in the wrong place — the window has closed. Open the app again to be refused again, and the button returns.
The second catch is that the decision is permanent. Apple: the app “is now saved as an exception to your security settings, and you can open it in the future by double-clicking it, just as you can any authorized app”. There is no expiry and no reminder. You are not opening the file once; you are adding it to the list of things this Mac trusts.
One setting sits above all of this, under Privacy & Security, Security, “Allow apps downloaded from”: App Store, or App Store and identified developers. If your Mac only offers the stricter option, or offers neither, Apple gives the reason: “these settings might not be available if your Mac is managed by a system administrator or IT department”. On a work Mac that is the answer, and the right next step is to ask them rather than to look for a way around it.
Three files, three answers
The same alert, and why the right decision is not the same one each time.
Why the answers to this question are nearly always just clicks. Both of the pages this one draws on are Apple’s own, and neither is hard to find. What gets repeated is the three-step override, because that is what someone stuck in front of a dialogue box asks for. What gets dropped is the sentence that decides whether to take those steps at all, and the fact that the message never claimed to have found anything. An answer that hands you the click and omits both is answering a shorter question than the one that was asked.
If the alert was the other one. A Mac that says an app “will damage your computer” has detected something, and that is a different job: removing malware from a computer covers the sequence and what a clean scan does not settle. If the warning arrived in a browser window rather than from macOS, it is not from your Mac at all — that kind of security alert is a web page, whichever operating system it names.
Where to start
Three ways in.
- “Do I have a virus?”
- What the message says — what it means
- “Should I open it anyway?”
- Apple’s own warning — the warning
- “Where is the button?”
- The hour, and the exception — how to open
When something really was found
This page is about a message that reports no detection. These are for when there is one.
The same question on other devices
What each system will and will not let you install is the difference between these guides.
Questions people also ask
What does Apple could not verify is free of malware mean?
That the app was not notarised, so Apple never examined it. Apple’s wording is that if the developer cannot be verified and the app “hasn’t been notarized by Apple, macOS can’t verify that the app is free of malware”. Nothing was found because nothing was checked.
Does this message mean the app has a virus?
No. macOS uses a different alert when it detects something: it says the app “will damage your computer”, and for known malware it refuses to open the app and moves it to the Trash. If you saw the “cannot verify” wording, no detection happened.
How do I open an app macOS will not let me open?
Try to open it and let it be refused, then open System Settings, click Privacy & Security, scroll to Security and click Open Anyway, confirm at the second prompt and enter your login password. Apple advises checking the App Store or an alternative app first.
Why is there no Open Anyway button in Privacy & Security?
Because the window has passed. Apple states the button “is available for about an hour after you try to open the app”. Open the app again so it is refused again, then go straight to Privacy & Security and the button will be there.
Is it safe to click Open Anyway?
Apple’s own answer is a warning: “overriding security settings to open an app is the most common way that a Mac gets infected with malware”, and you should not do it for an unchecked app “even if the app looks like it comes from a major developer”.
Can I undo it after clicking Open Anyway?
The permission does not expire on its own. Apple states the app is “saved as an exception to your security settings” and opens normally from then on, so the way back is to remove the app itself rather than to withdraw the approval.
Not covered here. It does not tell you whether your particular file is safe, and no page can. What it does is separate what macOS actually said from what it is usually read as saying, so the decision is yours on the real information.
It does not cover the command line methods for stripping the quarantine attribute. Those bypass the check rather than answer it, and the point of this page is the check.
And it does not cover a managed Mac, where the setting may be absent by policy. Apple says so directly, and the answer there is the administrator rather than a workaround. What holds instead is simple: the difference between the two alerts is quoted from Apple’s own support page, the warning about overriding is quoted in full from Apple’s Mac User Guide rather than summarised, the one-hour window and the permanent exception are Apple’s own words, and the page says plainly that no page can tell you whether your particular file is safe.
Sources
- Apple Support — Safely open apps on your Mac, updated 27 May 2026: the five alerts macOS can display and what each means, including that an unverified developer and an app that has not been notarised is why “macOS can’t verify that the app is free of malware”; that a notarised app “indicates that Apple checked it for malicious software and none was detected”; the separate alerts for software with malicious content and for known malware moved to the Trash; the override steps; the two “Allow apps downloaded from” settings and that they may be unavailable on a managed Mac — support.apple.com, read 9 September 2026.
- Apple Mac User Guide — Apple can’t check app for malicious software: the statement that overriding security settings is the most common way a Mac gets infected with malware and that you should not do it even if the app looks like it comes from a major developer; the advice to look for the app in the Mac App Store or for an alternative first; and the override steps including that the Open Anyway button is available for about an hour after the attempt and that the app is then saved as an exception — support.apple.com, read 9 September 2026.
- National Cyber Security Centre — Antivirus and other security software, Device security guidance: the reasoning that a device which can only run software delivered through a monitored store gains very limited value from antivirus, which is the same argument that macOS’s notarisation check is built on — www.ncsc.gov.uk, read 9 September 2026.
Written by Alberto Gulotta
Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.
Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.
Written on 9 September 2026.
Independence and limits
No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.
This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.