Apple macOS High Sierra has a huge security vulnerability
时间:2024-09-23 05:32:36 出处:产品中心阅读(143)
Well this isn't good. A bug in Apple macOS High Sierra can let anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.
Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.
Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.
Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.
Tweet may have been deleted
Tweet may have been deleted
Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.
However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.
Tweet may have been deleted
Tweet may have been deleted
"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."
Instructions to do so can be found on an Apple support page.
This story has been updated with information about remote exploitation, as well as a statement from Apple.
Featured Video For You
This eco-friendly fabric can repel stains and odors
猜你喜欢
- Apple Watch 10 rumors: Everything we know so far
- P.M. vacancy raises concern
- The Sony WH
- Starving artist Justin Bieber's credit card was declined at Subway
- 16 of the Most Epic Sandwiches Around the Planet
- Tesla issues recall for 9,100 Model X cars
- N. Korea tries to use artificial intelligence to write malicious software: US official
- 牧原5年狂掷41亿搞研发,海大研究生最多!你认为哪家企业最有前景?
- 'Metaphor: ReFantazio' hands