The vulnerability on macOS 10.13 allows access to the Mac with any password
First discovered by the Open Radar, this security hole allows unlocking the settings in the App Store via the System Preference if the Mac is locked and has a lock icon in the left corner.
Normally, the user will not lock it but there is a message saying 'Click the lock image to avoid further changes'. Blocking will prevent automatic updates, install new macOS, security updates or system files.
Lock icon in the left-hand corner to open
Access without user name or password
Try it on macOS High Sierra 10.13.2, here are the steps:
- Click System Preferences
- Click the App Store
- Click on the lock icon if available
- Click on the lock icon again
- Enter your username and any password
- Click Unlock
This error is worse than the previous Mac lock error because no user name is required, because the authentication dialog only asks for a password and the username is usually filled out. If you go somewhere, forget to unlock it for a while.
But when it is locked, everyone can access it
With this vulnerability, anyone can get administrative rights on the Mac, change the settings related to macOS updates, security patches.
Experiment with this error on two completely successful Macs, allowing access to App Store settings in Preferences with any password, including a letter or a number. Even the part of the username you want to enter is okay.
According to the MacRumors, the error no longer works on the macOS High Sierra 10.3.3 Beta, meaning Apple has overcome it. But many people still use macOS 10.13.2, 10.13.1 or even 10.13. And version 10.13.3 is still in Beta and this month will be officially released.
See more:
- Looking back at Apple 2017
- Apple released macOS unlocking patch, with apology
- Apple is preparing to combine iOS and Mac applications as one
You should read it
- Error on macOS allows creating root account without password
- The method of Crack Passwords
- Forgot password protected Excel file, what should you do?
- iOS 12 can prevent USB devices from unlocking iPhone
- The newly released macOS has detected a serious security vulnerability
- Break hotspot password on iOS within 1 minute
- How does macOS High Sierra unlock? How to stop?
- Updating to macOS 10.13.1 brings the root error back
May be interested
- Intel released Microcode for CPU Linux to fix Meltdown and Specteron january 8, intel released micro-data files for linux microprocessors to mitigate the effects of meltdown and specter vulnerabilities.
- This is a way to protect Linux Mint from Meltdown and Specternew linux developers have officially voiced the two vulnerabilities of meltdown and specter, suggesting ways to help users protect their computers.
- Apple transferred management rights to iCloud in China to local companiesapple has just announced that it will transfer the right to operate icloud service on the chinese market to a local company to comply with its laws.
- Intel patch causes a reboot error on older processorsmany times, fixing the error also causes things worse than the error itself.
- Will the global Internet be broken if all of the undersea cable lines are attacked?optical fiber lines running along the ocean contain almost all digital communication globally. so if something is wrong or a terrorist organization attacks the undersea cable, what terrible thing will happen.
- Apple postponed the replacement of the new iPhone battery for $ 29 for failing to meet demanddue to the sudden increase in battery replacement demand and unsold battery capacity, customers using non-aging iphone models will have to wait until early q2 / 2018 to replace the new battery. as required.