macOS High sierra is vulnarable
by this vulnerabilities hacker can steal all your password which is stored or running in high sierra.
according to the researcher Patrick wardle, he was able to run an unsigned and unauthentic app in the new OS update that could steal plain text passwords. he posted evidence in twitter and included a link to a video the app name is "keychainStealer"
He later said "I discovered a flaw where malicious non-privileged code (or apps) could programmatically access the keychain and dump all this data .... including your plain text passwords,on High Sierra (unsigned) apps can programmatically dump & exfil keychain (w/ your plaintext passwords)🍎🙈😭 vid: https://t.co/36M2TcLUAn #smh pic.twitter.com/pqtpjZsSnq— patrick wardle (@patrickwardle) September 25, 2017
He also notice that the EI CAPTAIN is also vulnareble as well which is the previous version then sierra.
but it is not so easy for hacker also he said "first we have to infect the targeted computer and then we can do some thing to that computer"
there is also a video on vimeo of that vulnerability
Steal y0 (macOS) Keychain from patrick wardle on Vimeo.
Comments
Post a Comment