【Watch Angel Has Fallen Online】
Apple's latest and Watch Angel Has Fallen Onlinegreatest operating system, macOS High Sierra, hit the digital airwaves on September 25 — promising a free upgrade to Macs around the world with at least 2GB of memory. And while the OS is chock-full of exciting new features, it's the vulnerabilities that have at least one security researcher excited.
That's because it turns out that, with just a little bit of effort, hackers can steal all your passwords off a computer running High Sierra. Which, frankly, is not a good look for Apple.
SEE ALSO: Apple is cleaning up account security in macOS High SierraAccording to security researcher Patrick Wardle, he was able to run an unsigned app on the new OS that could steal plaintext passwords. He posted evidence of his proof of concept to Twitter, and included a link to a video demonstrating an app he dubbed "keychainStealer."
This Tweet is currently unavailable. It might be loading or has been removed.
"I discovered a flaw where malicious non-privileged code (or apps) could programmatically access the keychain and dump all this data .... including your plain text passwords," he explained on Patreon. "This is not something that is supposed to happen!"
Importantly, he noted that while he has only tested High Sierra, it appears that El Capitan is vulnerable as well. But the news isn't all bad, as Wardle emphasized that for this to work your computer would first have to be infected with malware.
"As this is a local attack, this means a hacker or piece of malware must firstinfect your your Mac," Wardle reassured concerned readers. "Typical ways to accomplish this include emails (with malicious attachments), fake web popups ("your Flash player needs updating"), or sometimes legitimate application websites are hacked (e.g. Transmission, Handbrake, etc)."
Apple, for its part, isn't that impressed with the exploit — although a spokesperson confirmed they are looking into it.
"macOS is designed to be secure by default, and [Apple security feature] Gatekeeper warns users against installing unsigned apps, like the one shown in this proof of concept, and prevents them from launching the app without explicit approval," the spokesperson told Mashablevia email. "We encourage users to download software only from trusted sources like the Mac App Store, and to pay careful attention to security dialogs that macOS presents.”
This Tweet is currently unavailable. It might be loading or has been removed.
Wardle, meanwhile, is thankfully not looking to steal all your passwords. Instead, he contacted Apple about the exploit before going public and believes the company's engineers are in the process of patching the High Sierra holes.
"As my discovery of this bug and report (in early September) was 'shortly' before High Sierra's release, this did not give Apple enough time to release a patch on time," he wrote. "However, my understanding is a patch will be forthcoming!"
Essentially, it all boils down to this: Don't download sketchy apps, and make sure you always update your OS to the latest version in order to receive any and all patches. And, regardless of the specific threat posed by Wardle's findings, that's some basic security advice to live by.
Featured Video For You
We got our hands on the iPhone 8 - here's everything you need to know
Topics Apple Cybersecurity
Search
Categories
Latest Posts
Control-Alt-Fail
2025-06-25 22:542020 laws that give us hope for the year ahead
2025-06-25 22:30Woody Harrelson has apparently quit smoking weed
2025-06-25 20:56Underwater Photographer of the Year 2022: The winning photos
2025-06-25 20:30Popular Posts
Brand on the Run
2025-06-25 23:00Where to watch Golden Globe
2025-06-25 22:18Trump wants the border wall to be tall, strong and hot. Smoking hot.
2025-06-25 21:00The Deal of the Art
2025-06-25 20:28Featured Posts
The Longest Miles
2025-06-25 23:06Woman who fought off bathroom attacker has strong message for anti
2025-06-25 23:02New Lyft and Uber rules to know for New Year's Day
2025-06-25 22:55Glimpse into Amazon's futuristic living spheres
2025-06-25 21:44Popular Articles
Comrades at Arms
2025-06-25 22:58A decade of New Year's Eve glasses, ranked by how dumb they looked
2025-06-25 21:31Woman who fought off bathroom attacker has strong message for anti
2025-06-25 21:16Signs and Blunders
2025-06-25 21:12Newsletter
Subscribe to our newsletter for the latest updates.
Comments (47123)
Music Information Network
Boys to Men
2025-06-25 23:06Reality Information Network
Woman who fought off bathroom attacker has strong message for anti
2025-06-25 22:53Thought Information Network
Thousands told to jump into the ocean as Australia's raging fires approached
2025-06-25 22:38Exquisite Information Network
10 video games we can't wait to play in 2020
2025-06-25 22:23Storm Information Network
The Miseducation of <i>Lady Bird</i>
2025-06-25 20:55