Apple's latest and Watch Captain Hooker and Peter Porn (1987)greatest operating system, macOS High Sierra, hit the digital airwaves on September 25 — promising a free upgrade to Macs around the world with at least 2GB of memory. And while the OS is chock-full of exciting new features, it's the vulnerabilities that have at least one security researcher excited.
That's because it turns out that, with just a little bit of effort, hackers can steal all your passwords off a computer running High Sierra. Which, frankly, is not a good look for Apple.
SEE ALSO: Apple is cleaning up account security in macOS High SierraAccording to security researcher Patrick Wardle, he was able to run an unsigned app on the new OS that could steal plaintext passwords. He posted evidence of his proof of concept to Twitter, and included a link to a video demonstrating an app he dubbed "keychainStealer."
This Tweet is currently unavailable. It might be loading or has been removed.
"I discovered a flaw where malicious non-privileged code (or apps) could programmatically access the keychain and dump all this data .... including your plain text passwords," he explained on Patreon. "This is not something that is supposed to happen!"
Importantly, he noted that while he has only tested High Sierra, it appears that El Capitan is vulnerable as well. But the news isn't all bad, as Wardle emphasized that for this to work your computer would first have to be infected with malware.
"As this is a local attack, this means a hacker or piece of malware must firstinfect your your Mac," Wardle reassured concerned readers. "Typical ways to accomplish this include emails (with malicious attachments), fake web popups ("your Flash player needs updating"), or sometimes legitimate application websites are hacked (e.g. Transmission, Handbrake, etc)."
Apple, for its part, isn't that impressed with the exploit — although a spokesperson confirmed they are looking into it.
"macOS is designed to be secure by default, and [Apple security feature] Gatekeeper warns users against installing unsigned apps, like the one shown in this proof of concept, and prevents them from launching the app without explicit approval," the spokesperson told Mashablevia email. "We encourage users to download software only from trusted sources like the Mac App Store, and to pay careful attention to security dialogs that macOS presents.”
This Tweet is currently unavailable. It might be loading or has been removed.
Wardle, meanwhile, is thankfully not looking to steal all your passwords. Instead, he contacted Apple about the exploit before going public and believes the company's engineers are in the process of patching the High Sierra holes.
"As my discovery of this bug and report (in early September) was 'shortly' before High Sierra's release, this did not give Apple enough time to release a patch on time," he wrote. "However, my understanding is a patch will be forthcoming!"
Essentially, it all boils down to this: Don't download sketchy apps, and make sure you always update your OS to the latest version in order to receive any and all patches. And, regardless of the specific threat posed by Wardle's findings, that's some basic security advice to live by.
Topics Apple Cybersecurity
Howard vs Wagner basketball livestream: How to watch liveNYT's The Mini crossword answers for March 20Trump's NASA nominee faces tough questions on views of LGBTQ rightsSheep show off intelligence by recognizing human facesBest earbuds deal: The Echo Buds with noise cancellation are just $54.99 at AmazonGet Kindle Paperwhite Signature Edition for $30 off with a PrimeBest earbuds deal: The Echo Buds with noise cancellation are just $54.99 at AmazonTrump science agency nominee is not a climate denierThreads rolls out trending topics for all users in the U.S.TCU vs. USU basketball livestreams: How to watch liveTesla Autopark is getting a new name, and it's very LOTRNYT's The Mini crossword answers for March 18Trump's top environment pick made some bonkers climate science claimsHow to watch the Microsoft Surface event 2024Truecaller has an AI upgrade for Android users to block robocallsAmazon Big Spring Sale wireless earbud deals: Save big on Echo Buds and moreWe wish this insanely creepy pre'Civil War' isn't out yet, but the internet is already going to war over itSpaceX will launch a secret government payload to orbit ThursdayThe best fitness tracker deals from Amazon's Big Spring Sale Prince Harry and Meghan Markle sign major deal with Netflix The best coming This sick skateboarding kitten is cooler than you Here are the emails that Donald Trump Jr. didn't want you to see It's fine to swear in front of your kids, according to this mom who is totally f*cking right A tired journalist's response to Trump Jr.'s emails has spawned a great meme Facebook threatens to block all news from being shared in Australia Singles don't want to date non Naomi Osaka honors Breonna Taylor during US Open match Blaux portable air conditioner, your constant Instagram ad, isn't worth it These dogs have been DNA tested. Can you guess the breed? Dave Grohl is in an adorable remote drum battle with a 10 Twitter's 'Quote Tweet' changes make sussing out online drama easier New Ubisoft Tom Clancy game called out for insensitive framing of BLM 8 times Chadwick Boseman used his celebrity to be a real What is an algorithm? Triller makes play to buy U.S. TikTok, report claims Amazon gets FAA approval to fly Prime Air delivery drones Chrissy Teigen shuts down 'rose ice cream' with 1 very blunt tweet Donald Trump Jr.'s emails just sparked the most frustrating grammar debate
2.6282s , 8228.796875 kb
Copyright © 2025 Powered by 【Watch Captain Hooker and Peter Porn (1987)】,Fresh Information Network