会员登录 - 用户注册 - 设为首页 - 加入收藏 - 网站地图 Apple macOS High Sierra has a huge security vulnerability!

Apple macOS High Sierra has a huge security vulnerability

时间:2024-09-22 22:27:12 来源:摩登家庭人人影视网 作者:新闻中心 阅读:246次

Well this isn't good. A bug in Apple macOS High Sierra can let anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.

Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.

Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.

Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.

However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.

"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."

Instructions to do so can be found on an Apple support page.

This story has been updated with information about remote exploitation, as well as a statement from Apple.


Featured Video For You
This eco-friendly fabric can repel stains and odors

(责任编辑:新闻中心)

相关内容
  • GPU Mining is Dead, Where are my Cheap GPUs?
  • 汉源警方捣毁贩毒吸毒盗窃团伙 46名涉案人员落网
  • Elon Musk's not
  • Ben Carson tells CNN Holocaust could have been different if Jews had guns.
  • What to expect from Apple's September event: iPhone 16, Apple Watch 10, and more
  • Police officer bitten by woman, loses part of finger
  • Pastor and activist Moon Tong
  • Malaysia Airlines Flight 17 crash: Long
推荐内容
  • SpaceX Polaris Dawn mission: How to watch the launch
  • Illinois lottery short on cash starts paying IOUs.
  • Democrats will propose bill closing background check loopholes; it will likely fail.
  • Roaring Kitty reveals massive GME position in GameStop stock gamble
  • U.S. Senators call on FTC to investigate the security of drivers' data
  • Singer Jung Joon