ALERT: There’s A Massive Security Vulnerability In The New MacOS

The current release of macOS High Sierra, version 10.13.1, has a bug that allows someone with physical access to your machine to bypass the log-in screen and access your data. The issue allows someone to authenticate as a “system administrator” with the ability to view files and change details in user accounts.

macOS’ underpinnings are the Darwin Unix distribution. And, like all Unix systems, there is a root user that has complete control over everything. This is a level of access that is well in excess of a normal admin account that is created when adding users on a Mac.

The bug was reported by Lemi Orhan Ergin who reached out to Apple over Twitter.

According to The Verge, one way to thwart this low likelihood but high impact vulnerability is to change the root account password on your Mac. This is done by

  1. Open System Preferences and launch Users & Groups
  2. Go to Login Options, click on Join and then Open Directory Utility
  3. Choose the Edit option and Enable the Root User if you haven’t already
  4. Choose Change Root Password

Although Apple does run a bug bounty program, offering rewards of up to US$200,000, it’s invitation only unlike the wide open programs run by Microsoft, Google and others.

This flaw is significant but the risk to most users is quite low. In order to exploit the issue, a bad guy would need physical access to your Mac. And, as most security experts would attest, physical access will eventually trump any logical security you may have in place.


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments


Leave a Reply