Hacking

A flaw in macOS High Sierra allows to unlock the App Store Preferences without password

Security expert discovered a new vulnerability in macOS High Sierra that could be exploited by users logged as admins to unlock the AppStore Preferences in System Preferences by providing any password.

Security expert discovered a new vulnerability in macOS High Sierra that could be exploited by users logged as admins to unlock the AppStore Preferences in System Preferences by providing any password.

The vulnerability was reported by Eric Holtam and affects the latest version macOS 10.13.2. The issue doesn’t affect non-admin accounts that must provide correct credentials to unlock the AppStore Preferences.

The steps to reproduce the issue and grants access to change the AppStore preferences are:

  1. Log in as a local admin;
  2. Open App Store Prefpane from the System Preferences;
  3. Lock the padlock if it is already unlocked;
  4. Click the lock to unlock it;
  5. Enter any bogus password;

Holtam highlighted that the issue doesn’t affect other system preferences panel (i.e. system preferences).

The flaw has a limited impact because it can only be triggered by admins, anyway, anyone with a physical access to a machine that was left unattended by a user logged as admins can exploit the vulnerability.

Apple already issued a security patch in the latest beta version of macOS High Sierra (10.13.3) and the problem will be addressed in a future update for stable versions.

In November, an authentication bypass issue was publicly disclosed via Twitter by the developer Lemi Orhan Ergan. The flaw in macOS High Sierra allowed gaining root access to a machine with no password.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – macOS High Sierra, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

U.S. Treasury removed sanctions against the crypto mixer service Tornado Cash<gwmw style="display: none; background-color: transparent;"></gwmw>

The U.S. Treasury is lifting sanctions on Tornado Cash, a crypto mixer accused of helping…

4 hours ago

Zero-day broker Operation Zero offers up to $4 million for Telegram exploits

Russian zero-day broker Operation Zero is looking for exploits for the popular messaging app Telegram,…

21 hours ago

RansomHub affiliate uses custom backdoor Betruger<gwmw style="display:none;"></gwmw>

Symantec researchers linked a custom backdoor, called Betruger, found in recent ransomware attacks to an…

1 day ago

Cisco Smart Licensing Utility flaws actively exploited in the wild

Experts warn of the active exploitation of two recently patched security vulnerabilities affecting Cisco Smart…

2 days ago

Pennsylvania State Education Association data breach impacts 500,000 individuals

A data breach at the Pennsylvania State Education Association exposed the personal information of over…

2 days ago

Veeam fixed critical Backup & Replication flaw CVE-2025-23120

Veeam released security patches for a critical Backup & Replication vulnerability that could let attackers…

2 days ago

This website uses cookies.