Major flaw in macOS High Sierra puts your passwords at risk

Apple has launched the latest version of macOS, High Sierra, with an unpatched zero-day vulnerability in place, a worrying state of affairs even though the flaw is one which theoretically won’t affect the majority of users (at least those who take heed of Gatekeeper’s warnings).

The exploit was discovered by Patrick Wardle, chief security researcher at ‎Synack, and also affects earlier versions of macOS (and OS X for that matter).

  • Tune into the latest developments surrounding the MacBook Pro

It can be delivered by an unsigned app, and is capable of hoovering up all the passwords stored in the macOS keychain (in plain-text, so fully readable), without needing the master password normally required to access the keychain. The user won’t realize anything bad has happened.

Of course, if you try to install an unsigned app under macOS, the operating system will warn you against proceeding. And that’s exactly what Apple pointed out in its defense.

As at ZDNet reports, the company stated: “MacOS is designed to be secure by default, and Gatekeeper warns users against installing unsigned apps, like the one shown in this proof of concept, and prevents them from launching the app without explicit approval.

“We encourage users to download software only from trusted sources like the Mac App Store, and to pay careful attention to security dialogs that macOS presents.”

Fix frustrations

However, Wardle reported the exploit earlier this month, and is disappointed that Apple hasn’t managed to fix the problem for the launch of High Sierra, given that this is a nasty bug that can whip away all your passwords.

And there’s always the prospect of some nefarious type managing to get the exploit into a digitally-signed app, which has happened in the past (using a falsified registration for Apple’s developer program, or indeed simply stolen developer credentials). That would make this threat far more dangerous, of course.

On the subject of revealing the vulnerability before it has been patched, Wardle told ZDNet: “As a passionate Mac user, I'm continually disappointed in the security of macOS … every time I look at macOS the wrong way something falls over. I felt that users should be aware of the risks that are out there – I'm sure sophisticated attackers have similar capabilities.”

Hopefully, now the malware cat is out of the bag in this case, Apple will move swiftly to issue a patch. In the meantime, be careful what you’re installing on your Mac (although that should be your default perspective on software downloads anyway).

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in macOS
macOS Catalina
A secret project, a stubborn developer, and a lot of glossy icons: here's the story behind macOS’s Dock as it turns 25
A woman sitting on a couch cross-legged and using a laptop
Essential apps and features to start getting the most out of your brand-new Mac
A woman sitting at a table with various objects on it, including a MacBook, a mug, a book, an opened notebook, and holding her head with her hands as if in frustration
It looks like macOS Sequoia 15.2 update breaks third-party bootable backups - and that has me worried
Genmoji Cowboy Frog Apple Intelligence
macOS Sequoia 15.3 beta brings Genmoji to Mac, allowing you to serve up custom emojis that really represent you
Person using a MacBook sat on sofa
Your Mac’s menu bar will finally get a weather widget in macOS Sequoia 15.2 – plus these Apple Intelligence features
The Apple Magic Mouse on a white surface next to the Magic Keyboard.
Planning to buy Apple’s new USB-C Magic accessories? Make sure you’re running macOS Sequoia 15.1 first
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over