While Apple scrambles to issue a software fix for a major macOS High Sierra vulnerability, astute observers are wondering what took the company so long to react — after all, the problem was known about weeks ago.
It seems that on November 13, a commenter on an Apple developer forum disclosed the very vulnerability that today threw the infosec community into a frenzy. Oh, and it was called out 9 days ago on Twitter as well.
SEE ALSO: How to protect yourself from the massive macOS High Sierra security vulnerabilityAnd just how bad is this security threat? Well, it's not good. Essentially, it gives anyone with access to an unlocked computer the ability to set themselves as the root user — as well as log back in later to the locked computer at a time of their choosing.
To execute the hack, you only needed to go to System Preferences >Users & Groups, then enter "root" as your user name while leaving the password field blank. Try this a few times until you have access. It's that simple. The exploit was first explained by Apple developer chethan177.
Again, chethan177 posted this on November 13. Apple only issued instructions on how to protect yourself against this on November 28.
Tweet may have been deleted
Tweet may have been deleted
Whether or not anyone tried to responsibly disclose the threat with Apple remains unclear. But the fact that this attack — which in some cases can be performed remotely — was known to some developers weeks before Apple issued a statement about it is sure to turn heads.
Mashablehas reached out to Apple for comment and will update the story as soon as we hear back.
Copyright © 2023 Powered by
MacOS High Sierra vulnerability publicly disclosed weeks ago-声闻过情网
sitemap
文章
73649
浏览
325
获赞
87413
12 interesting gadgets to spice up your self
May is National Masturbation Month, and we're celebrating with Feeling Yourself, a series exploringIf TikTok is banned in the U.S., this is what it will look like for everyone else
In just a matter of days, the lights will switch off on the app that has almost dominated, and certaBest coffee machine deal: Save $50 on Nespresso Vertuo Pop+
SAVE $50: As of Jan. 16, the Nespresso Vertuo Pop+ is on sale for $129.99 at Amazon. That's a 28% saLyft riders will now be able to earn JetBlue points
Ride a Lyft, get a frequent flyer mile. Customers who take Lyft to the airport will be able to earnHBO Max vs. HBO Go and HBO Now: What makes each service different
There are now three streaming services with HBO's name on them. Wednesday marked the official launchThis startup wants to deliver affordable contact lenses straight to your door
By now it's a familiar narrative in startup circles: you can make millions by disrupting industriesHackers are targeting your password manager app
Do you use 1Password, LastPass, NordPass, or any other password manager? You're not alone. AccordingBest tablet deal: Save $45 on Amazon Fire HD 10 tablet
SAVE $45:As of Feb. 4, the Amazon Fire HD 10 tablet is on sale for $94.99 at Amazon. That's a savingFacebook insists new Workplace tool was for 'preventing bullying,' not suppressing unions
Facebook wants to empower you to make the world more open and connected as you suppress your workersTrump supporters celebrate their victory on Twitter
LONDON -- The votes have been counted and a winner announced.And in 2016 what do you do when you winBest Samsung deal: Take 23% off the Samsung Galaxy S24 Ultra
SAVE $300:The unlocked Samsung Galaxy S24 Ultra (256GB) is on sale at Best Buy for $999.99, down froNo America, this is not an episode of 'Black Mirror'
We know what you're thinking -- and we've seen your Twitter jokes -- but no, this is not a dark draWe shot Portrait mode video with this iPhone app
Ever take a Portrait mode photo on your iPhone and wish you could do the same with video?Well, you'rHey 2016, here are all the times you sucked in one image
Dear 2016,You're the worst.No seriously -- from the death of some of the most talented artists in thHow tech billionaires learned to love Trump
The sight of Elon Musk, Jeff Bezos and Mark Zuckerberg sitting together at Donald Trump's inaugurati