CONFERENCE On Demand: Cyber AI & Automation Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

macOS High Sierra Update Patches Keychain Access Flaw

An update released on Thursday by Apple for its macOS High Sierra operating system patches two vulnerabilities, including one that allows malicious applications to steal passwords from the Keychain.

An update released on Thursday by Apple for its macOS High Sierra operating system patches two vulnerabilities, including one that allows malicious applications to steal passwords from the Keychain.

The Keychain flaw, tracked as CVE-2017-7150, was disclosed last week by Patrick Wardle, director of research at Synack. Apple has now addressed the issue with the release of High Sierra 10.13 Supplemental Update.

The researcher warned that High Sierra and previous versions of macOS are affected by a security hole that can be exploited by unsigned applications to programmatically dump and exfiltrate sensitive data from the Keychain, including plaintext passwords. However, he only released a video demonstrating the attack, without making any technical details public.

“A method existed for applications to bypass the keychain access prompt with a synthetic click. This was addressed by requiring the user password when prompting for keychain access,” Apple said in its advisory.

SecurityWeek has reached out to Wardle to find out if the latest update properly patches the vulnerability he found. This article will be updated once the researcher responds.

Wardle also demonstrated recently how Apple’s new Secure Kernel Extension Loading (SKEL) security feature, introduced in High Sierra, can be easily bypassed.

The High Sierra 10.13 Supplemental Update also fixes a password disclosure issue involving encrypted Apple File System (APFS) volumes.

Brazil-based developer Matheus Mariano discovered that passwords set by users via Disk Utility for new encrypted APFS volumes are displayed in clear text via the “Show Hint” button when the volume is mounted. The problem only appears to affect encrypted APFS volumes created via Disk Utility.

Advertisement. Scroll to continue reading.

“This was addressed by clearing hint storage if the hint was the password, and by improving the logic for storing hints,” Apple said about the flaw, which it tracks as CVE-2017-7149.

Apple has also published a knowledge base article for the password leakage issue. The company has advised users to protect their existing APFS volumes by creating a backup, erasing the existing volume, and restoring the initial volume to set a new password.

“Changing the password on an affected volume clears the hint but doesn’t affect the underlying encryption keys that protect the data,” Apple said.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join us as we delve into the transformative potential of AI, predictive ChatGPT-like tools and automation to detect and defend against cyberattacks.

Register

As cybersecurity breaches and incidents escalate, the cyber insurance ecosystem is undergoing rapid and transformational change.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...