> How does Apple check against malicious software? What is even considered "malicious" software?

It's an automated check that Apple has not disclosed.

I see how this can help protect against outright malware. However, what if there's a flaw in the heuristics, and some malware slips through the cracks? Sure, they can fix their malware scanner, but will they take the time to retroactively scan all software with their new and improved scanner? Will they even store every single notarized app on their servers for this to be feasible? Or will they mandate re-notarization every now and then?

So many questions, hopefully Apple answers these soon.

Edit: phrasing

They can revoke certificates and add the software to XProtect's blacklist.

