Apple code signing can be bypassed. for added lulz, the bug seems to be on the signing side, not verification side, so all 3rd party apps need to be rebuilt before new checks can be deployed by Apple (you can't distinguish real signature from fake)
https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/
Post #530
166