Table of Contents
Newly released to the public today as Apple's latest macOS High Sierra operating system has an important security hole, allowing hackers to access Plainted Keychain Data.
The Newly Released macOS Has Detected a Serious Security Vulnerability Overview
Unregistered applications on macOS High Sierra (and possibly the previous version of macOS) can steal usernames and account passwords stored on Keychain.
Security researcher and former NSA analyst Patrick Wardle talked about this vulnerability and shared a video of how to exploit it.
In order for this vulnerability to work, users need to download third-party malicious code from an unknown source, Apple often discourages users from downloading applications from untrusted developers or from outside the Mac App Store. Apple does not even allow downloading from untrusted developers without overwriting security settings.
In the video illustrated, Wardle creates a POC application called keychainStealer that can access the plaintext passwords of Twitter, Facebook and Bank of America stored on Keychain.
An attacker can steal data on Plaintext Keychain
Wardle told Forbes about the vulnerability and said it was not too difficult to run malicious code on the Mac even with Apple's protection. Wardle does not provide the entire exploit code, but he also believes Apple will fix the vulnerability in the next update.
Apple has not responded when asked about this vulnerability.
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does the Newly Released macOS Has Detected a Serious Security Vulnerability matter?
Newly released to the public today as Apple's latest macOS High Sierra operating system has an important security hole, allowing hackers to access Plainted Keychain Data.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.