Jump to content

macOS High Sierra security flaw gives anyone full admin access – no password needed


Recommended Posts

A Turkish software developer has publicly revealed via Twitter that he has uncovered a massive security bug in macOS High Sierra, Apple’s latest operating system. 

The flaw grants anyone using a Mac machine admin access by just clicking ‘other’ on the login screen and using ‘root’ as the username, no password needed.

In fact, access to the computer can also be achieved using the username ‘root’ via System Preferences where, to change essential settings on locked Mac devices, users would normally need to enter their login details.

This bug seems to present in macOS High Sierra 10.13.1 – the current version – as well as in the macOS 10.13.2 beta, but does not affect older versions of macOS, like Sierra or El Capitan.

This doesn’t bode well for users on the latest release of macOS – leaving a Mac unattended could make anyone system administrator without any authentication, even when accessed remotely, revealing sensitive information.

Apple has confirmed that it is aware of the bug and is “working on a software update to address the issue.” The Cupertino-based giant released a statement describing how users can, in the meantime, temporarily fix the vulnerability by enabling the root user with a password.

http://feeds.feedburner.com/~r/techradar/software-news/~4/CGZcC9DV_q8
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...