The newly released macOS has detected a serious security vulnerability
Newly released to the public today as Apple's latest MacOS High Sierra operating system has an important security hole, allowing hackers to access Plainted Keychain Data.
Newly released to the public today as Apple's latest MacOS High Sierra operating system has an important security hole, allowing hackers to access Plainted Keychain Data.
Unregistered applications on macOS High Sierra (and possibly the previous version of macOS) can steal usernames and account passwords stored on Keychain.
Security researcher and former NSA analyst Patrick Wardle talked about this vulnerability and shared a video of how to exploit it.
In order for this vulnerability to work, users need to download third-party malicious code from an unknown source, Apple often discourages users from downloading applications from untrusted developers or from outside the Mac App Store. . Apple does not even allow downloading from untrusted developers without overwriting security settings.
In the video illustrated, Wardle creates a POC application called keychainStealer that can access the plaintext passwords of Twitter, Facebook and Bank of America stored on Keychain.
An attacker can steal data on Plaintext Keychain
Wardle told Forbes about the vulnerability and said it was not too difficult to run malicious code on the Mac even with Apple's protection. Wardle does not provide the entire exploit code, but he also believes Apple will fix the vulnerability in the next update.
Apple has not responded when asked about this vulnerability.
- Update your Macbook now to avoid this major security bug
- Detected critical zero-day vulnerability on Adobe Reader
- Detected a serious zero-day vulnerability in Microsoft Office, click the document file and it will stick
- Apple patched many zero-day bugs in iOS 15.4.1 and macOS 12.3.1 updates
- Mac computers stuck with a dangerous security vulnerability, Apple was announced in February but has not yet resolved
- Microsoft discovered a critical vulnerability on macOS
- Google announced a serious vulnerability in the macOS kernel
- Apple releases iOS 14.4.2, iOS 12.5.2, and watchOS 7.3.3 updates that patch the critical zero-day vulnerability
- Detected extremely serious vulnerability in Hikvision security cameras
- Protect yourself against IE security holes
- Apple expanded the size of the security bug detection program to receive bonuses, including macOS, a maximum bonus of $ 1 million
- Detecting a serious security vulnerability on macOS, this 18-year-old youth refused to disclose it because Apple did not pay the bonus
- The researcher released code that exploits the iOS Kernel vulnerability
- iOS 11.1 was released with a series of new emoji and fixes for the KRACK vulnerability