Major Apple security flaw grants admin access on macOS High Sierra without password
The critical vulnerability was publicly disclosed on Twitter
by Chris Welch
/cdn.vox-cdn.com/uploads/chorus_image/image/57777581/akrales_170717_1831_0084.0.jpg)
Photo by Amelia Holowaty Krales / The Verge
There’s a major flaw in Apple’s macOS High Sierra operating system that allows anyone with physical access to a Mac to gain system administrator access without so much as entering a password. Late Tuesday, Apple confirmed that it’s working on a software update to fix the issue and published step-by-step instructions to help customers protect their machines in the meantime.
The vulnerability was publicly disclosed on Twitter this afternoon; it’s not clear whether the problem was privately reported to Apple ahead of time, which is the encouraged practice when security vulnerabilities are uncovered. (The company maintains an invite-only bug bounty program.) Despite its incredibly alarming simplicity, The Verge is not reproducing the steps to bypass High Sierra’s login screen here. It does not affect Sierra or other previous macOS versions.
/cdn.vox-cdn.com/uploads/chorus_asset/file/9772775/Screenshot_2017_11_29_09.23.05_preview.jpg)
The level of unbridled access this security hole permits — and it abruptly being made public — will almost certainly prompt Apple to move fast in releasing an update for its Mac operating system. The company hasn’t yet provided a release timeframe for that update.
Until that happens, the best way to protect your Mac against the issue reported today is by ensuring that you’ve set a root password. To do that, go to System Preferences > Users & Groups > Login Options > Join > Open Directory Utility > Edit pulldown menu. Enable the Root User if you haven’t already and then choose Change Root Password. (Thanks, dyavuz!)
The Verge has reached out to Apple for further details.
No comments:
Post a Comment