This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.
https://unit42.paloaltonetworks.com/gatekeeper-bypass-macos/
https://support.apple.com/en-us/HT213185