Apple's latest and Watch The Heirs Onlinegreatest operating system, macOS High Sierra, hit the digital airwaves on September 25 — promising a free upgrade to Macs around the world with at least 2GB of memory. And while the OS is chock-full of exciting new features, it's the vulnerabilities that have at least one security researcher excited.
That's because it turns out that, with just a little bit of effort, hackers can steal all your passwords off a computer running High Sierra. Which, frankly, is not a good look for Apple.
SEE ALSO: Apple is cleaning up account security in macOS High SierraAccording to security researcher Patrick Wardle, he was able to run an unsigned app on the new OS that could steal plaintext passwords. He posted evidence of his proof of concept to Twitter, and included a link to a video demonstrating an app he dubbed "keychainStealer."
This Tweet is currently unavailable. It might be loading or has been removed.
"I discovered a flaw where malicious non-privileged code (or apps) could programmatically access the keychain and dump all this data .... including your plain text passwords," he explained on Patreon. "This is not something that is supposed to happen!"
Importantly, he noted that while he has only tested High Sierra, it appears that El Capitan is vulnerable as well. But the news isn't all bad, as Wardle emphasized that for this to work your computer would first have to be infected with malware.
"As this is a local attack, this means a hacker or piece of malware must firstinfect your your Mac," Wardle reassured concerned readers. "Typical ways to accomplish this include emails (with malicious attachments), fake web popups ("your Flash player needs updating"), or sometimes legitimate application websites are hacked (e.g. Transmission, Handbrake, etc)."
Apple, for its part, isn't that impressed with the exploit — although a spokesperson confirmed they are looking into it.
"macOS is designed to be secure by default, and [Apple security feature] Gatekeeper warns users against installing unsigned apps, like the one shown in this proof of concept, and prevents them from launching the app without explicit approval," the spokesperson told Mashablevia email. "We encourage users to download software only from trusted sources like the Mac App Store, and to pay careful attention to security dialogs that macOS presents.”
This Tweet is currently unavailable. It might be loading or has been removed.
Wardle, meanwhile, is thankfully not looking to steal all your passwords. Instead, he contacted Apple about the exploit before going public and believes the company's engineers are in the process of patching the High Sierra holes.
"As my discovery of this bug and report (in early September) was 'shortly' before High Sierra's release, this did not give Apple enough time to release a patch on time," he wrote. "However, my understanding is a patch will be forthcoming!"
Essentially, it all boils down to this: Don't download sketchy apps, and make sure you always update your OS to the latest version in order to receive any and all patches. And, regardless of the specific threat posed by Wardle's findings, that's some basic security advice to live by.
Topics Apple Cybersecurity
Previous:Literature Shrugged
Next:Operation Snowflake
Google reveals I/O 2018 developer conference dates: May 8Apple 'iPhone SE 2' with have wireless charging, report saysGame developers are losing interest in VR as it fails to catch onStop acting like you don’t know your Tinder date’s last name2018 Grammys red carpet: See looks from Lady Gaga, Kelly Clarkson and moreIt's canon: Poe Dameron really is a dreamboat, according to bookStop acting like you don’t know your Tinder date’s last nameAndrew Lincoln will narrate Harry Potter audiobook about QuidditchParis flooding of 2018, as captured in social media photos and videosApple HomePod first impressions: Great sound is a good startWhy the JaySnapchat update lets you share camera roll pics without white bordersSnapchat update lets you share camera roll pics without white bordersGoogle reveals I/O 2018 developer conference dates: May 8Here's how Apple is bringing medical records to your iPhoneReese Witherspoon has 3 legs: A 'Vanity Fair' Photoshop storyWhy you should watch 'Paddington 2' this weekendTide Pods and Valentine's Day go hand in hand this yearParis flooding of 2018, as captured in social media photos and videosAlphabet just launched Chronicle, a new cybercrime company from its moonshot factory Why do 'Normal People' edits still dominate TikTok? Cooking with Eileen Chang by Valerie Stivers Best early Cyber Monday laptop deals 2023 from Apple, Dell, so much more ‘Girl, Interrupted,’ Twenty 180+ early Cyber Monday gaming deals: Nintendo Switch, Xbox, and more The Saddest Children’s Book in the World by Yevgeniya Traps Staff Picks: Creek Boyz, Mechanical Chickens, and Trash Heaps by The Paris Review Behold, 20 of the funniest YouTube videos ever, according to Reddit In Memory of Stanley Cavell The Melancholy of the Hedgehog Best early Cyber Monday AirPods deals: AirPods Pro at record On Stanley Kunitz and the Fine Arts Work Center by Geoffrey Hilsabeck Staff Picks: Bandits, Revenge, and Decapitated Animals by The Paris Review Wordle today: The answer and hints for November 26 Witches, Artists, and Pandemonium in ‘Hereditary’ 300+ early Cyber Monday deals: Amazon, Apple, Walmart, more Who Are You, Jack Whitten? by Jack Whitten Early Cyber Monday: Dyson Airwrap multi Edouard Louis and Abdellah Taïa in Conversation Early Cyber Monday unlocked phone deals: Apple, Google, Samsung, more
2.9494s , 8223.0390625 kb
Copyright © 2025 Powered by 【Watch The Heirs Online】,Defense Information Network