As Apple fixes macOS root password hole, here's what went wrong
https://www.theregister.co.uk/2017/11/29/apple_macos_high_sierra_root_bug_patch/
Code dive Apple has emitted an emergency software patch to address the trivial to exploit vulnerability in macOS High Sierra, version 10.13.1, that allowed miscreants to log into Macs as administrators without passwords and let any app gain root privileges.
The Cupertino iPhone giant kicked out the fix, Security update 2017-001, today after word of the bug and methods to exploit it ran wild over the internet. It was discussed on Apple's developer support forums two weeks ago, and hit Twitter on Tuesday.
As Apple fixes macOS root password hole, here's what went wrong
Nov 29, 2017, 8:33pm UTC
https://www.theregister.co.uk/2017/11/29/apple_macos_high_sierra_root_bug_patch/
>Code dive Apple has emitted an emergency software patch to address the trivial to exploit vulnerability in macOS High Sierra, version 10.13.1, that allowed miscreants to log into Macs as administrators without passwords and let any app gain root privileges.
>The Cupertino iPhone giant kicked out the fix, Security update 2017-001, today after word of the bug and methods to exploit it ran wild over the internet. It was discussed on Apple's developer support forums two weeks ago, and hit Twitter on Tuesday.