Apple has just released an update to XProtect for macOS Sequoia and later

Apple has just released its regular weekly update to XProtect, bringing it to version 5357. However, this week’s has so far only been released via iCloud for macOS Sequoia and later. As usual it doesn’t release information about what security issues this update might address.

This version adds five new Yara rules for CROOKEDCRUSTACEAN.IMPLANT.A, MACOS.ODYSSEY.XOOB, MACOS.SHADYSHOELACE.RUOP, MACOS.SHADYSHOELACE.BUAR and MACOS.SHADYSHOELACE.DEPA, and amends the rule for MACOS.BONZAIBONANZA.VACA. In the Osascript rules in XPScripts.yr, it adds five new rules for MACOS.OSASCRIPT.TITEST, MACOS.OSASCRIPT.TIPAHA, MACOS.OSASCRIPT.TIKEGR, MACOS.OSASCRIPT.TISASH and MACOS.OSASCRIPT.TIINCO, and amends MACOS.OSASCRIPT.SYPR.

You can check whether this update has been installed by opening System Information via About This Mac, and selecting the Installations item under Software.

A full listing of security data file versions is given by SilentKnight and SystHist for El Capitan to Golden Gate available from their product page. If your Mac hasn’t yet installed this update, you can force it using SilentKnight or at the command line.

If you want to install this as a named update in SilentKnight, its label is XProtectPlistConfigData_10_15-5357

Sequoia, Tahoe and Golden Gate systems only

This update has so far only been released for Sequoia and later via iCloud. If you want to check it manually, use the Terminal command
sudo xprotect check
then enter your admin password (this still results in an error in macOS 27, though). If that returns version 5357 but your Mac still reports an older version is installed, you should be able to force the update using
sudo xprotect update
which should work fine for Golden Gate as well.

This has now been released for older macOS as well.