Jump to content

[UNPATCHED] Major Apple security flaw grants admin access on macOS High Sierra without password

ItsMitch
14 minutes ago, Dan Castellaneta said:

This sounds intentional for all the wrong reasons.

It is intentional.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

24 minutes ago, Daring said:

Don't worry guys, working as intended!

 

I guess we can close this for not being news. 

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, huilun02 said:

I'm sure @DrMacintosh can explain this login method's existence. You shouldn't worry about having your nudes leaked id your macbook gets stolen. Apple is infallible.

Your last sentence is going to trigger so many people. Be careful. Nothing in security is infallible. There's always a way to break security features and people will find a way to exploit it.

 

Just look at the many ways you can bypass the lockscreen in iOS 11. Granted, they don't provide full access, but does allow unauthorized access to contacts and photos. 

Intel® Core™ i7-12700 | GIGABYTE B660 AORUS MASTER DDR4 | Gigabyte Radeon™ RX 6650 XT Gaming OC | 32GB Corsair Vengeance® RGB Pro SL DDR4 | Samsung 990 Pro 1TB | WD Green 1.5TB | Windows 11 Pro | NZXT H510 Flow White
Sony MDR-V250 | GNT-500 | Logitech G610 Orion Brown | Logitech G402 | Samsung C27JG5 | ASUS ProArt PA238QR
iPhone 12 Mini (iOS 17.2.1) | iPhone XR (iOS 17.2.1) | iPad Mini (iOS 9.3.5) | KZ AZ09 Pro x KZ ZSN Pro X | Sennheiser HD450bt
Intel® Core™ i7-1265U | Kioxia KBG50ZNV512G | 16GB DDR4 | Windows 11 Enterprise | HP EliteBook 650 G9
Intel® Core™ i5-8520U | WD Blue M.2 250GB | 1TB Seagate FireCuda | 16GB DDR4 | Windows 11 Home | ASUS Vivobook 15 
Intel® Core™ i7-3520M | GT 630M | 16 GB Corsair Vengeance® DDR3 |
Samsung 850 EVO 250GB | macOS Catalina | Lenovo IdeaPad P580

Link to comment
Share on other sites

Link to post
Share on other sites

Both iOS 11 and High Sierra seems to have escaped quality control. Granted, this security bug in high sierra can be prevented by enabling full disk encryption using File Vault. 

 

But then, let’s not pretend that other desktop operating systems haven’t experienced this so hopefully Apple releases a software update quickly. Maybe Apple should change their employees who are responsible for testing their software. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, hey_yo_ said:

Both iOS 11 and High Sierra seems to have escaped quality control. Granted, this security bug in high sierra can be prevented by enabling full disk encryption using File Vault. 

 

But then, let’s not pretend that other desktop operating systems haven’t experienced this so hopefully Apple releases a software update quickly. Maybe Apple should change their employees who are responsible for testing their software. 

I can't speak for macOS, but iOS 11 is very sloppy. 11.2 fixed some stuff, but it still just feels rushed. They need to stop with the one year cycles of major updates. If anything, its more like 6 months. Because soon WWDC will roll around and iOS 12 will get unveiled. Seems like the same for macOS as well.

5800X3D / ASUS X570 Dark Hero / 32GB 3600mhz / EVGA RTX 3090ti FTW3 Ultra / Dell S3422DWG / Logitech G815 / Logitech G502 / Sennheiser HD 599

2021 Razer Blade 14 3070 / S23 Ultra

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, vetali said:

I can't speak for macOS, but iOS 11 is very sloppy. 11.2 fixed some stuff, but it still just feels rushed. They need to stop with the one year cycles of major updates. If anything, its more like 6 months. Because soon WWDC will roll around and iOS 12 will get unveiled. Seems like the same for macOS as well.

Whenever Linus says that iOS 11 is awesome on previous WAN show episodes, part of me wants to throw my iPhone because iOS 11 is the dumbest and shittiest iOS release to date. Never before have I ever experienced so many iOS bugs than iOS 11 which makes me question if Craig Federighi has the right staff for software quality control. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, ARikozuM said:

I guess we can close this for not being news. 

hmm...

Apple released a statement to the press with the following about the exploit:

Quote

An Apple spokesperson said in an emailed statement: "We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the ‘Change the root password’ section."

more like, "sorry we forgot this shit was in lol, we'll remove it we guess"

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, SC2Mitch said:

hmm...

Apple released a statement to the press with the following about the exploit:

more like, "sorry we forgot this shit was in lol, we'll remove it we guess"

That doesn't make any sense... the problem here is that you can get into the root account with no password by clicking the button a few times.  Telling people "setting a root password prevents unauthorized access to your Mac." is just straight up denying this exploit exists which makes no sense since they acknowledged it just a sentence prior...

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ryan_Vickers said:

That doesn't make any sense... the problem here is that you can get into the root account with no password by clicking the button a few times.  Telling people "setting a root password prevents unauthorized access to your Mac." is just straight up denying this exploit exists which makes no sense since the acknowledged it just a sentence prior...

Yeah, it's bit weird, pushing it under the rug maybe? 

Link to comment
Share on other sites

Link to post
Share on other sites

OP says “thank fuck I don’t own a Mac” 

 

But in order to be affected by this you have to have an unattended Mac or had one stolen and even know what the hell the root user is in MacOS. 

 

That being said it is a stupid whole and is apparently already being fixed. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Just now, SC2Mitch said:

Yeah, it's bit weird, pushing it under the rug maybe? 

I can't imagine what they mean by that.  It's like if someone broke into your house and the lock company told you "well, we'll look into that but locking your doors prevents unauthorized access to your home".  Like, what? xD

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

19 minutes ago, hey_yo_ said:

Whenever Linus says that iOS 11 is awesome on previous WAN show episodes, part of me wants to throw my iPhone because iOS 11 is the dumbest and shittiest iOS release to date. Never before have I ever experienced so many iOS bugs than iOS 11 which makes me question if Craig Federighi has the right staff for software quality control. 

Should probably Restore. 

 

On iOS 11.1.2 with an iPhone 6s Plus and the only issue so far is that screenshots don’t always upload to iCloud and save locally when I want to send them in a messaging app. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

25 minutes ago, hey_yo_ said:

Whenever Linus says that iOS 11 is awesome on previous WAN show episodes, part of me wants to throw my iPhone because iOS 11 is the dumbest and shittiest iOS release to date. Never before have I ever experienced so many iOS bugs than iOS 11 which makes me question if Craig Federighi has the right staff for software quality control. 

Yeah I thought that as well when Linus said that. And he said that way back when it was first released. Luckily my biggest issue was fixed: it completely destroying battery life on my 6s and 8 plus. I also dunno what apple did, but predictive text is completely garbage now. I use the default apple keyboard because nobody has really replicated the 3d touch to move your cursor freely in the textbox as well as the apple keyboard. Used to be good enough in 10. Now its almost unbearable.

5800X3D / ASUS X570 Dark Hero / 32GB 3600mhz / EVGA RTX 3090ti FTW3 Ultra / Dell S3422DWG / Logitech G815 / Logitech G502 / Sennheiser HD 599

2021 Razer Blade 14 3070 / S23 Ultra

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, vetali said:

predictive text is completely garbage now.

Often with restores or updates the predictive text AI is reset, you have to use it to for it to know what you might want to type. 

 

For me the only change I have noticed is that it randomly duplicates words when it corrects misspelled ones. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, vetali said:

I use the default apple keyboard because nobody has really replicated the 3d touch to move your cursor freely in the textbox as well as the apple keyboard.

I haven't used the stock Apple keyboard in quite a long time, but Gboard has implemented the force touch to move the cursor as well as being able to move the cursor by sliding on the spacebar and it works well imo.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, djdwosk97 said:

I haven't used the stock Apple keyboard in quite a long time, but Gboard has implemented the force touch to move the cursor as well as being able to move the cursor by sliding on the spacebar and it works well imo.

gboards cursor movement is a ghetto knock off of apples. Its much worse.

5800X3D / ASUS X570 Dark Hero / 32GB 3600mhz / EVGA RTX 3090ti FTW3 Ultra / Dell S3422DWG / Logitech G815 / Logitech G502 / Sennheiser HD 599

2021 Razer Blade 14 3070 / S23 Ultra

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, vetali said:

gboards cursor movement is a ghetto knock off of apples. Its much worse.

You tempted me, I checked it out and it is significantly better. The lack of swype and the worse prediction is a dealbreaker for me though, as much as I do like the better cursor navigation. 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

3 hours ago, hey_yo_ said:

Both iOS 11 and High Sierra seems to have escaped quality control.

rumor says both of the OS arent "fully baked" yet... but apple rushes to put them out because it has to be a yearly thingy.... a.k.a the October iphone release event 

If it is not broken, let's fix till it is. 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, mrchow19910319 said:

rumor says both of the OS arent "fully baked" yet... but apple rushes to put them out because it has to be a yearly thingy.... a.k.a the October iphone release event 

For a company known to excel in optimizing software with existing hardware, they're starting to falter on that aspect.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

23 minutes ago, hey_yo_ said:

For a company known to excel in optimizing software with existing hardware, they're starting to falter on that aspect.

as much as I love apple, you are absolutely right. I never thought one day macOS will cause me these much trouble. went to apple store more than 3 times just to "set everything right" and I am tech savvy enough to try all the solution I can find online as well as all the solution apple support recommended me. and the OS is STILL having small issues here and there right now..... 

 

welp.....no 1st day update from now on... 

If it is not broken, let's fix till it is. 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, mrchow19910319 said:

as much as I love apple, you are absolutely right. I never thought one day macOS will cause me these much trouble. went to apple store more than 3 times just to "set everything right" and I am tech savvy enough to try all the solution I can find online as well as all the solution apple support recommended me. and the OS is STILL having small issues here and there right now..... 

 

welp.....no 1st day update from now on... 

Maybe Apple needs to fire both Jony Ive for weird, asymmetrical designs and Craig Federighi for too much software bugs on iOS and macOS.

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, mrchow19910319 said:

as much as I love apple, you are absolutely right. I never thought one day macOS will cause me these much trouble. went to apple store more than 3 times just to "set everything right" and I am tech savvy enough to try all the solution I can find online as well as all the solution apple support recommended me. and the OS is STILL having small issues here and there right now..... 

 

welp.....no 1st day update from now on... 

What kind of bugs? I'm still running El Capitan because I've been too lazy to upgrade to Sierra and then High Sierra.....but I was going to get around to it sooner or later.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

50 minutes ago, djdwosk97 said:

What kind of bugs? I'm still running El Capitan because I've been too lazy to upgrade to Sierra and then High Sierra.....but I was going to get around to it sooner or later.

Disclaimer: not everyone runs into these kind of bugs... this is just an individual thing. 

 

1 hour ago, hey_yo_ said:

Maybe Apple needs to fire both Jony Ive for weird, asymmetrical designs and Craig Federighi for too much software bugs on iOS and macOS.

I dont give a shit about jony ive. BUt personally I really like craig federfighi. At least he is more authentic and energetic whenever he is on stage. 

If it is not broken, let's fix till it is. 

Link to comment
Share on other sites

Link to post
Share on other sites

Stupid vulnerability but it seems kinda familiar. Didn't Linux have something similar some months back? Something with repeating a certain action like 17 times giving full access? Although it does seem like in Apple's case it was almost intentional.

 

Also, is the root 'account' always enabled? If I recall on Windows you need to enable it yourself and on Linux you're prompted/supposed to change the root password.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×