MacOS High Sierra vulnerability publicly disclosed weeks ago

新闻中心 2024-09-22 09:44:27 686

While Apple scrambles to issue a software fix for a major macOS High Sierra vulnerability, astute observers are wondering what took the company so long to react — after all, the problem was known about weeks ago.

It seems that on November 13, a commenter on an Apple developer forum disclosed the very vulnerability that today threw the infosec community into a frenzy. Oh, and it was called out 9 days ago on Twitter as well.

SEE ALSO:How to protect yourself from the massive macOS High Sierra security vulnerability

And just how bad is this security threat? Well, it's not good. Essentially, it gives anyone with access to an unlocked computer the ability to set themselves as the root user — as well as log back in later to the locked computer at a time of their choosing.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

To execute the hack, you only needed to go to System Preferences >Users & Groups, then enter "root" as your user name while leaving the password field blank. Try this a few times until you have access. It's that simple. The exploit was first explained by Apple developer chethan177.

Again, chethan177 posted this on November 13. Apple only issued instructions on how to protect yourself against this on November 28.

Whether or not anyone tried to responsibly disclose the threat with Apple remains unclear. But the fact that this attack — which in some cases can be performed remotely — was known to some developers weeks before Apple issued a statement about it is sure to turn heads.

Mashablehas reached out to Apple for comment and will update the story as soon as we hear back.


Featured Video For You
This eco-friendly fabric can repel stains and odors
本文地址:http://1.zzzogryeb.bond/html/42b099079.html
版权声明

本文仅代表作者观点,不代表本站立场。
本文系作者授权发表,未经许可,不得转载。

全站热门

World’s first ‘meltdown

强降雨致多处塌方 未出现较大灾情

日访客量破万 累计交易近7千笔

广州春耕正当时!2012.51万元农机补贴已下达

夜间献血模式“上线”

全市外贸工作培训会召开

尼泊尔8.1级地震牵动雅安人民的心

佛冈县高岗豆腐节:“兜福”闹元宵,万人开启豆腐大战

友情链接