While Apple scrambles to issue a software fix for a major macOS High Sierra vulnerability,homo eroticism in western comics astute observers are wondering what took the company so long to react — after all, the problem was known about weeks ago.
It seems that on November 13, a commenter on an Apple developer forum disclosed the very vulnerability that today threw the infosec community into a frenzy. Oh, and it was called out 9 days ago on Twitter as well.
SEE ALSO: How to protect yourself from the massive macOS High Sierra security vulnerabilityAnd just how bad is this security threat? Well, it's not good. Essentially, it gives anyone with access to an unlocked computer the ability to set themselves as the root user — as well as log back in later to the locked computer at a time of their choosing.
To execute the hack, you only needed to go to System Preferences >Users & Groups, then enter "root" as your user name while leaving the password field blank. Try this a few times until you have access. It's that simple. The exploit was first explained by Apple developer chethan177.
Again, chethan177 posted this on November 13. Apple only issued instructions on how to protect yourself against this on November 28.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
Whether or not anyone tried to responsibly disclose the threat with Apple remains unclear. But the fact that this attack — which in some cases can be performed remotely — was known to some developers weeks before Apple issued a statement about it is sure to turn heads.
Mashablehas reached out to Apple for comment and will update the story as soon as we hear back.
Topics Apple Cybersecurity
(Editor: {typename type="name"/})
China just built the world's biggest floating solar project
Twitter CEO Jack Dorsey gives himself a 'C' in 'tech responsibility'
'Metro Exodus' breaks the 'Metro' mold in a sort of boring way: Review
'Pokémon Go' adds the AR photos feature you've been waiting for
Clean energy projects soared in 2016 as solar and wind got cheaper
The major issue that was ignored in the presidential debate
Ken Bone's glorious red sweater is sold out
The government won't require people to fax their consent forms anymore
Swole Jeff Bezos joins Instagram to tease his new ROCKET FACTORY
Donald Trump and his debate chair get a whirlwind Photoshop battle
接受PR>=1、BR>=1,流量相当,内容相关类链接。