Tag Archive for: Root

Updating macOS can bring back the nasty “root” security bug

Enlarge (credit: Andrew Cunningham)

The serious and surprising root security bug in macOS High Sierra is back for some users, shortly after Apple declared it fixed. Users who had not installed macOS 10.13.1 (and thus were running a prior version of the OS when they received the security update) found that installing 10.13.1 resurfaced the bug, according to a report from Wired.

For these users, the security update can be installed again (in fact, it would be automatically installed at some point) after updating to the new version of the operating system. However, the bug is not fixed in that case until the user reboots the computer. Many users do not reboot their computers for days or even weeks at a time, and Apple’s support documentation did not, at first, inform users that they needed to reboot. So some people may have been left vulnerable without realizing it. The documentation has been updated with the reboot step now.

The root bug allows anyone to log in or authenticate as a system administrator on systems running macOS High Sierra. In many circumstances, all they need to do is simply type in the username “root” and leave the password field blank, . The bug was so serious that it drew an uncharacteristically strong apology from Apple, which said its “customers deserve better.”

Read 1 remaining paragraphs | Comments

Biz & IT – Ars Technica

Apple fixes root password bug: ‘Install this update as soon as possible’

Apple fixes root password bug: 'Install this update as soon as possible'

To their credit, it didn’t take Apple long to fix their horrendous bug that allowed *anyone* to log into computers running macOS High Sierra with admin rights, without needing to know a password.

But it should really never have got past quality control in the first place.

Graham Cluley

Debugging Tool Left on OnePlus Phones, Enables Root Access

Phone maker OnePlus is being blasted for leaving a developer debugging app on its handsets allowing phones to be rooted by an attacker with physical access to the device.
Threatpost | The first stop for security news

New program to root out vulnerabilities in third-party apps on Google Play – Myjoyonline.com


Myjoyonline.com

New program to root out vulnerabilities in third-party apps on Google Play
Myjoyonline.com
Google is introducing a new program to help root out vulnerabilities in third-party apps in its Google Play storefront. The Google Play Security Reward Program will pay researchers who discover problems in popular Android apps found in the store.

android security – read more