Apple updated the password revealing patch from the Disk Utility function
Apple has just released an emergency update for macOS High Sierra to fix errors that expose passwords that are encrypted in APFS format via password hint feature.
The new bug was discovered by Leet Tech security researcher Matheus Mariano and posted the video below.
This problem only appears on macOS High Sierra when the user adds an encrypted APFS file. Then, the user is asked to enter the password before accessing the data and when entering the hint button, the full password will be displayed instead of just the suggested password.
The full password will appear instead of the suggested password
Only Mac SSD drives and APFS formats are affected
The error only occurs when the user fills in the suggested password. If not, it will be fine. This issue also affects only SSD drives, where new APFS file systems are supported.
Apple released additional updates
Compared to other times of error reporting, this time Apple acted quickly to fix. Users are advised to update or at least delete the suggested password.
In addition, Apple also offers support pages with step by step instructions for backing up, deleting and restoring encrypted APFS files after OS updates.https://support.apple.com/en-us/HT208168
Similar updates also patched the zero-day vulnerability in the Keychain application, causing the plaintext password to be exposed. This vulnerability was discovered by researcher Patrick Wardle.
see more
The newly released macOS has detected a serious security vulnerability
You should read it
- How to change the default macOS Sierra wallpaper
- Useful tips for macOS 10.12 Sierra
- How to fix common errors when upgrading to macOS Sierra
- Updating to macOS 10.13.1 brings the root error back
- How to customize message notifications on macOS Sierra
- Which items need attention when cleaning up memory on macOS?
- How to change the shortcut to use Siri on macOS Sierra
- Do you know 3 window management features on macOS Sierra?
May be interested
- Google: Dangerous for users when Microsoft does not patch Windows the same way on the OSgoogle's leading security team, project zero, said that microsoft is putting users at risk when there is no uniformity when patching the windows operating system versions.
- Forget about data theft, hacker hijack Amazon cloud account to dig bitcoinmoney may not grow from trees, but it can grow from amazon web services (aws) ..
- The suspect on the network was arrested after the provider shared VPN access history with the FBIvpn service providers often advertise their products as a way to surf the web anonymously, that they never record user activity. but a recent case shows that there are at least a few units that record user activity history.
- Outlook may not encrypt your email if you use S / MIME encryptionusers using microsoft outlook to send encrypted email via the s / mime standard may experience information leaks due to errors in outlook.
- Features available on MS Office allow malware to enter without turning on the macrosince cybercriminals appear more and more, traditional techniques become more mysterious when exploiting standard tools and protocols that are often overlooked.
- Akamai detected the Fast Flux botnet with 14,000 IP addressesresearchers at akamai have discovered a botnet with more than 14,000 ip addresses used to spread malware, using smart technology called fast flux.