Apple macOS High Sierra has a huge security vulnerability

资讯 2024-09-22 17:19:35 75

Well this isn't good. A bug in Apple macOS High Sierra can let anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.

Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.

Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.

Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.

However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.

"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."

Instructions to do so can be found on an Apple support page.

This story has been updated with information about remote exploitation, as well as a statement from Apple.


Featured Video For You
This eco-friendly fabric can repel stains and odors
本文地址:http://r.zzzogryeb.bond/html/50b199905.html
版权声明

本文仅代表作者观点,不代表本站立场。
本文系作者授权发表,未经许可,不得转载。

全站热门

Amazon Android Days sale 2024: Save on unlocked phones, tablets, and more

春节有哪些趣味数据?“异地投喂”成新年俗青岛单笔外卖最高2620元

吴莎痛斥劈腿声明发律师函 刘翔护妻:有事冲我来

《摆渡人》男神女神云集 导演:不是用明星圈钱

DOJ accuses TikTok of collecting and sharing users' personal views, as the app fights a ban

鐜嬪婧愶細閰哥敎鑻﹁荆璇濇彁妗坃涓浗灞变笢缃慱闈掑矝

关注!广东《水产养殖尾水排放标准》公开征求意见

交通银行独家主承全国首批“乡村振兴票据”

友情链接