Major macOS (incl. High Sierra) Keychain password extraction vulnerability to be addressed by Apple in update [Video]

A macOS vulnerability discovered by security researcher Patrick Wardle allows any app – signed or unsigned – to extract plain text passwords from Keychain. Wardle demonstrated the exploit with a proof of concept app, seen in the video below.

The vulnerability is a huge one, because Keychain data is secured by 256-bit AES encryption, which should make it virtually uncrackable – and because the bug affects all versions of macOS, including High Sierra …

more…

0 Response to "Major macOS (incl. High Sierra) Keychain password extraction vulnerability to be addressed by Apple in update [Video]"

Post a Comment