UPDATED 22:48 EDT / OCTOBER 05 2017

INFRA

Apple issues update to patch password vulnerabilities in High Sierra operating software

Apple Inc. has issued a security update for macOS High Sierra that patches a severe vulnerability identified in September that allows unsigned apps to capture plain-text passwords from the Mac keychain.

The High Sierra 10.13 Supplemental Update actually fixes two security issues, the previously discovered security issue in the Mac keychain as well as a newly identified vulnerability that allows passwords to be accessed via the Apple File System, also known as APFS.

The new vulnerability is described by Apple as a bug that may allow local attackers to “gain access to an encrypted APFS volume.” Should they be successful, they could obtain password information if a “hint was set in Disk Utility when creating an APFS encrypted volume.” In plain English, that means that for some wacky reason — likely bad coding — the actual password was stored as the password hint.

Describing the new vulnerability as “facepalming,” the security team at Sophos detailed in a blog post Thursday just how easy it is to access a password through a process that involves the High Sierra version of Disk Utility. “A bad look for Apple, letting a buggy system utility like that into a production release … but a creditable response by Apple in getting a fix out quickly,” Sophos added.

Mac users who have installed High Sierra are encouraged to install the update as soon as possible. To run the update, users should launch the App Store and click on the updates icon. When the update appears as a listing, click on the update button for it on the right. The installation takes two to three minutes to install and requires a restart to complete.

Image: Apple

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.