A day after it was revealed that macOS High Sierra had a massive security problem that allowed unauthorized users to easily log into a Mac with admin access, Apple has released a patch for the bug.
SEE ALSO: Apple's 10 biggest screw-ups, rankedYesterday Twitter user Lemi Ergin publicly revealed that if a user types "root" into the User Name field that comes up when making changes to System Preferences, and then hitting enter, the user will gain root-user access. They'll also be able to log into the Mac anytime simply by going to "Other" at login and typing the "root" username again.
This Tweet is currently unavailable. It might be loading or has been removed.
The security flaw apparently only exists on macOS 10.13.0 or later. Apple quickly published a seven-step workaround for preventing anyone from taking control of a Mac this way, and now the company has released an official patch in a security update (download it here). You'll need to be running the latest version of High Sierra (10.13.1) to implement it.
The notes in the security update say it specifically addresses the flaw. As for the cause, the notes say, "a logic error existed in the validation of credentials. This was addressed with improved credential validation."
An Apple spokesperson told Mashable:
Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.
When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.
We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.
Security problems and patches happen all the time, although they are rarely this egregious, or this easy to exploit. It's also just the latest high-profile software problem haunting Apple -- the company recently had to patch a bug on iPhones that would substitute the letter "i" with a strange "A[?]" character for some users.
文章
942
浏览
676
获赞
46441
Inside the online communities where straight guys help other straight guys get off
May is National Masturbation Month, and we're celebrating withFeeling Yourself, a series exploring tTrump's EPA wants to kill our most ambitious climate change plan
After President Donald Trump called coal "indestructible" last week while also expressing concern foUber adds 3 new features to ease your holiday travel
With the holidays right around the corner, Uber rolled out a new size option called "UberXXL," a newBest Buy 2024 Black Friday sale: Dates, upcoming doorbusters, and more
Table of ContentsTable of ContentsUPDATE: Nov. 18, 2024, 11:40 a.m. EST This story has been updatedTrump spelled 'forest' wrong and everyone made the same joke
Donald Trump's messaging on the fires in California has been, for the most part, woefully misguided.How to replace Google with ChatGPT Search as your default search engine
ChatGPT Search is here, challenging Google's dominance in the search engine realm. Curious about wheBest Google Pixel deal: Save $154 on the Google Pixel 9
SAVE $154: As of Nov. 11, the Google Pixel 9 is on sale at Amazon for $645. This deal saves you 19%Best headphone deal: JBL Tune 770NC headphones are $30 off
SAVE $30:As of Oct. 31, the JBL Tune 770NC noise-canceling headphones are on sale for $99.95 at AmazZoom hackers are spoofing HR meeting invites to steal user login info
Zoommay have fixedmany of its own security issues, but it’ll never be immune to hackers tryingThe best noise
Best noise-cancelling headphones and earbuds deals ahead of Black Friday Best headphoBest Black Friday Apple deal: Get $200 off MacBook Air with M3 chip
SAVE $200:As of Nov. 12, the 2024 MacBook Air with M3 chip is $200 off at Amazon, bringing the priceBest travel deal: Save 20% on a 2
SAVE 20%:The Tile Pro Bluetooth tracker 2-pack is on sale at Amazon for $47.99 with the on-page coupLenovo Flex 5G laptop now available through Verizon
5G isn't just for phones. Starting this week, you can buy a real, actual laptop that connects to theShop deals on Beats entire line
SAVE UP TO 51%:Beats headphones and speakers are on sale at Amazon. Shop the Beats Studio Pro headphBest Black Friday Beats deal: Save $70 on Studio3 headphones
SAVE $70:As of Nov. 27, Beats Studio3 headphones are on sale for $89 in Walmart's Black Friday sale.