Password exposing macOS bug found by German teenage hacker who refuses to disclose details to Apple

By Digit NewsDesk | Published on Feb 11 2019
Password exposing macOS bug found by German teenage hacker who refuses to disclose details to Apple
HIGHLIGHTS

The hack is a simple app that does not need administrative level access.

Apple iPhone XR 64GB at Lowest Price Ever

6.1" display | 50% Faster Graphics performance | TrueDepth camera

Click here to know more

Highlights:

  • A teenager has discovered a vulnarability in Mac OS.
  • The vulnarability gives hackers access to users' passwords.

First a 14-year old finds a vulnerability letting users eavesdrop using FaceTime Group chat. Now, 18-year-old German, Linus Henze, has discovered a vulnerability that leaves users' saved passwords exposed to hackers This could include passwords saved in the iCloud Keychain or even passwords to banking websites, social networking websites, email websites and streaming services like Netflix, Amazon and more. This is a macOS only bug but through the Keychain password saver, all your iOS devices' passwords can be accessed as well. Henze isn’t disclosing the bug and his findings to Apple. He tells Forbes that “the lack of payment for such research was behind his decision to keep the hack’s details secret from the Cupertino giant.”

Highlighting the vulnerability, Henze said that he could make an app that could read the data in the keychain without any requirement of permission from the victim. There are no special privileges or admin access required to run the app. Running a simple app is all that is necessary to access the information.

Henze suggests that a hacker could hide the malware into a legitimate app to get it onto a user's computer. He tells Forbes, “Or a user could be directed to a webpage that would launch rogue code. And because the attack could grab tokens for accessing the iCloud, it would be possible to take over an Apple ID and download they keychain from the company’s servers”

If you are thinking that Apple does offer a bug bounty, then know that the bug bounty initiative is invite-only and for iOS. Henze said “It's like they don’t really care about macOS. Finding vulnerabilities like this one takes time, and I just think that paying researchers is the right thing to do because we’re helping Apple to make their product more secure.”

Henze’s findings come just a few weeks after the Group FaceTime eavesdropping bug was discovered. The FaceTime bug was found by a 14-year-old who wanted to chat with his friends while playing Fortnite. He called one of his friends, and when the said friend didn't answer his phone, 14-year-old Grant Thompson swiped up to FaceTime another friend initiating a Group FaceTime call. During this call he could hear the audio from the first friend he had dialed. Apple is also facing a lawsuit with regards to the Group FaceTime Bug. You can read more about the lawsuit here and the FaceTIme bug here.  

Also read:

Microsoft Surface Pro 6, Surface Laptop 2 quietly launched in India

Hackers are using Google translate to steal your data

Google receives flak for not patching PNG vulnerability, researchers say millions of Android users still at risk

Videos

MacBook Air (2018) with Retina Display: All you need to know | Digit.in
logo
Digit NewsDesk

The guy who answered the question 'What are you doing?' with 'Nothing'.

Apple MacBook Air 2018

Advertisements

Trending Articles

Advertisements

latest articles

View All
Advertisements

Popular Mobile Phones

View All

Hot Deals

View All

Digit caters to the largest community of tech buyers, users and enthusiasts in India. The all new Digit in continues the legacy of Thinkdigit.com as one of the largest portals in India committed to technology users and buyers. Digit is also one of the most trusted names when it comes to technology reviews and buying advice and is home to the Digit Test Lab, India's most proficient center for testing and reviewing technology products.

We are about leadership-the 9.9 kind! Building a leading media company out of India.And,grooming new leaders for this promising industry.