Table of Contents
Apple has just released an emergency update for macOS High Sierra to fix errors that expose passwords that are encrypted in APFS format via password hint feature.
Apple Updated the Password Revealing Patch from the Disk Utility Function Overview
The new bug was discovered by Leet Tech security researcher Matheus Mariano and posted the video below.
This problem only appears on macOS High Sierra when the user adds an encrypted APFS file. Then, the user is asked to enter the password before accessing the data and when entering the hint button, the full password will be displayed instead of just the suggested password.
The full password will appear instead of the suggested password
Only Mac SSD Drives and APFS Formats Are Affected
The error only occurs when the user fills in the suggested password. If not, it will be fine. This issue also affects only SSD drives, where new APFS file systems are supported.
Apple Released Additional Updates
Compared to other times of error reporting, this time Apple acted quickly to fix. Users are advised to update or at least delete the suggested password.
In addition, Apple also offers support pages with step by step instructions for backing up, deleting and restoring encrypted APFS files after OS updates. https://support. apple. com/en-us/HT208168
Similar updates also patched the zero-day vulnerability in the Keychain application, causing the plaintext password to be exposed. This vulnerability was discovered by researcher Patrick Wardle.
See more The newly released macOS has detected a serious security vulnerability
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does apple Updated the Password Revealing Patch from the Disk Utility Function matter?
Apple has just released an emergency update for macOS High Sierra to fix errors that expose passwords that are encrypted in APFS format via password hint feature.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.