MacOS High Sierra zero-day shows Keychain passwords in plain text
Wed, 27th Sep 2017
FYI, this story is more than a year old
SARA BARKER
Copywriter and Senior News Editor
MacOS users who are starting the upgrade to High Sierra – and those who are using El Capitan – are vulnerable to a proof-of-concept attack that shows their online passwords in plain text, according to Synack security researcher Patrick Wardle.
He discovered that Mac Keychain, a native password management tool, can store online account usernames and passwords in plain text, allowing malicious applications direct access to the account details. However, the Keychain is generally protected by a master password.
Wardle revealed the details in a video that showed a demonstration of the attack.
Explore with AI
Related stories
Top stories
Docusign's next move: Own the contract, not just the signature
F5 launches AI security to monitor worker tool use
Cloudera & Mistral partner on sovereign enterprise AI
OpenSSL funds six Australian students for Prague conference
QBE: Mooted critical infrastructure penalties hint at cyber regulatory future