Skip to main content

A High Sierra bug in the MacOS update could make it easy to steal passwords

how to download MacOS High Sierra
Image used with permission by copyright holder
A security researcher as discovered a MacOS High Sierra bug that makes it easy for hackers to steal passwords and other hidden login credentials from a user’s system. The bug appears to give hackers the ability to access Keychain data in plaintext without knowing the master password.

The purpose of the Keychain is to hold on to various login credentials and other secretive information and to keep it hidden from prying eyes. Like third-party password managers, you’re only supposed to be able to access that information with a master password. With the bug in High Sierra though, it appears that unsigned apps are able to circumvent that safeguard entirely.

Recommended Videos

Discovered by ex-NSA analyst and security researcher Patrick Wardle (thanks MacRumors), the bug makes it possible to dump the contents of Keychain’s password storage, accessing everything from banking passwords, to your Facebook login in plaintext.

Steal y0 (macOS) Keychain

Perhaps even more concerning is that this bug may have existed for some time. Although it has been proven to work following the High Sierra update, it’s possible that it could also work with older versions of MacOS.

Please enable Javascript to view this content

The one silver lining to this news is that, as with many attacks from nefarious individuals, a High Sierra user would need to download a malicious application from somewhere other than the App Store for the exploit to work. That’s something that Apple and most security professionals would heavily discourage, though it does sometimes happen.

To prove that the exploit exists, Wardle crafted a malicious app called “KeychainStealer,” which was able to reveal his phony Bank of America, Twitter, and Facebook login details with little effort. Although he hasn’t revealed the exact method of attack, it stands to reason that if he can figure it out, others will be able to as well, especially now that they know it’s possible.

For that reason some may not like that Wardle has been transparent with his concerns, though this story stands a much greater chance of forcing Apple to fix the bug than if he’d kept it to himself.

Still, it’s possible that this announcement isn’t entirely altruistic. Wardle does operate a Patreon to help support the creation of security software under his Objective-See brand, so this announcement should drive some interest in it.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
The latest Mac Monterey update fixes some nasty bugs
The 2021 MacBook Pro with the lid open on a white table.

Apple's latest MacOS Monterey 12.3.1 update addresses the Bluetooth and display issues that have been plaguing Mac owners for several weeks.

Eligible Mac users can access and download the MacOS Monterey‌‌‌ 12.3‌‌.1 update through the Software Update section of System Preferences.

Read more
Latest MacOS update causing monitor and controller issues
The Mac Studio and Studio Display at Apple's Peek Performance event.

Mac owners updating to the latest version of Apple's operating system are experiencing problems with connectivity to select peripherals, including game controls, displays, and graphics cards housed inside eGPUs.

The problems stem from updates to the latest version of Apple's MacOS 12.3, with people turning to various blogs, forums, and Reddit to report these issues. Apple has not acknowledged or addressed these complaints, and it's unknown how widespread these problems are among MacOS 12.3 users.

Read more
The latest MacOS update is bricking some people’s Macs
Apple MacBook Pro front view showing display and keyboard..

Normally, we’d encourage you to always update to the latest version of your operating system. But some Mac users got more than they bargained for when they installed the latest MacOS Monterey 12.3 update -- it bricked their devices.

According to posts on Apple’s developer forums and on social media, the 12.3 update is causing all manner of issues, from simple error messages to infinite rebooting loops and completely bricked Macs. Attempting to upgrade from MacOS Monterey 12.2.1 or earlier appears to be causing the problems.

Read more