欢迎来到久草影视网

久草影视网

Apple macOS High Sierra has a huge security vulnerability

时间:2024-09-23 05:32:36 出处:产品中心阅读(143)

Well this isn't good. A bug in Apple macOS High Sierra can let anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.

Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.

Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.

Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.

However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.

"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."

Instructions to do so can be found on an Apple support page.

This story has been updated with information about remote exploitation, as well as a statement from Apple.


Featured Video For You
This eco-friendly fabric can repel stains and odors

分享到:

温馨提示:以上内容和图片整理于网络,仅供参考,希望对您有帮助!如有侵权行为请联系删除!

友情链接: