Apple fixes two High Sierra password bugs

0
191

0

(Image: CNET/CBS Interactive)

Apple has fixed two vulnerabilities in its Mac operating system that put passwords at risk of theft by hackers.

The company released the security fix Thursday, an Apple spokesperson told ZDNet.

Synack’s Patrick Wardle, who was credited with finding one of the now-fixed vulnerabilities, revealed a password-stealing bug just hours before High Sierra was released.

The bug let an attacker grab and steal every password in plain text using a malicious, unsigned app downloaded from the internet — without needing the user’s master Keychain password.

Apple fixed the bug by requiring users to enter their password before unlocking their Keychain.

Thursday’s security update also fixed another security vulnerability affecting encrypted volumes using Apple’s new file system, APFS, in which the volume’s password was stored as the password hint and could be revealed in plain text.

Apple acknowledged Matheus Mariano for finding the bug.

ZDNET INVESTIGATIONS

Leaked TSA documents reveal New York airport’s wave of security lapses

US government pushed tech firms to hand over source code

At the US border: Discriminated, detained, searched, interrogated

Millions of Verizon customer records exposed in security lapse

Meet the shadowy tech brokers that deliver your data to the NSA

Inside the global terror watchlist that secretly shadows millions

FCC chairman voted to sell your browsing history — so we asked to see his

With a single wiretap order, US authorities listened in on 3.3 million phone calls

198 million Americans hit by ‘largest ever’ voter records leak

Britain has passed the ‘most extreme surveillance law ever passed in a democracy’

Microsoft says ‘no known ransomware’ runs on Windows 10 S — so we tried to hack it

Leaked document reveals UK plans for wider internet surveillance

ZDNET INVESTIGATIONS

Leaked TSA documents reveal New York airport’s wave of security lapses

US government pushed tech firms to hand over source code

At the US border: Discriminated, detained, searched, interrogated

Millions of Verizon customer records exposed in security lapse

Meet the shadowy tech brokers that deliver your data to the NSA

Inside the global terror watchlist that secretly shadows millions

FCC chairman voted to sell your browsing history — so we asked to see his

With a single wiretap order, US authorities listened in on 3.3 million phone calls

198 million Americans hit by ‘largest ever’ voter records leak

Britain has passed the ‘most extreme surveillance law ever passed in a democracy’

Microsoft says ‘no known ransomware’ runs on Windows 10 S — so we tried to hack it

Leaked document reveals UK plans for wider internet surveillance

0