UPDATED 22:48 EDT / OCTOBER 05 2017

INFRA

Apple issues update to patch password vulnerabilities in High Sierra operating software

Apple Inc. has issued a security update for macOS High Sierra that patches a severe vulnerability identified in September that allows unsigned apps to capture plain-text passwords from the Mac keychain.

The High Sierra 10.13 Supplemental Update actually fixes two security issues, the previously discovered security issue in the Mac keychain as well as a newly identified vulnerability that allows passwords to be accessed via the Apple File System, also known as APFS.

The new vulnerability is described by Apple as a bug that may allow local attackers to “gain access to an encrypted APFS volume.” Should they be successful, they could obtain password information if a “hint was set in Disk Utility when creating an APFS encrypted volume.” In plain English, that means that for some wacky reason — likely bad coding — the actual password was stored as the password hint.

Describing the new vulnerability as “facepalming,” the security team at Sophos detailed in a blog post Thursday just how easy it is to access a password through a process that involves the High Sierra version of Disk Utility. “A bad look for Apple, letting a buggy system utility like that into a production release … but a creditable response by Apple in getting a fix out quickly,” Sophos added.

Mac users who have installed High Sierra are encouraged to install the update as soon as possible. To run the update, users should launch the App Store and click on the updates icon. When the update appears as a listing, click on the update button for it on the right. The installation takes two to three minutes to install and requires a restart to complete.

Image: Apple

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.