Well this isn't good. A bug in Apple macOS High Sierra can Watch D Cup Girl Real Naked Kidnapping Case Onlinelet anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.
Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.
Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.
Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.
However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."
Instructions to do so can be found on an Apple support page.
This story has been updated with information about remote exploitation, as well as a statement from Apple.
Topics Apple Cybersecurity
(Editor: {typename type="name"/})
Best keyboard deals: Save on Asus gaming keyboards at Amazon
Belkin's new wireless dock is almost like AirPower
'This Is Us' squanders its most heartfelt moment
Twitter has a strong message for Bernie Bros who think Trump and Hillary are the same
Best JBL deal: Save $80 on JBL Xtreme 4 portable speaker
Japan landed two rovers on an asteroid's surface after four years
BBC breaks down investigation into a mass killing in viral Twitter thread
This stunning photo exhibition showcases the beauty of Sikhs and turbans
What cracked the Milky Way's giant cosmic bone? Scientists think they know.
'Game of Thrones' to open filming locations as tourist attractions
Useful or Little Known Android Features
The Philadelphia Flyers revealed their new, horrifying mascot, Gritty
接受PR>=1、BR>=1,流量相当,内容相关类链接。