{"id":243360,"date":"2018-01-02T17:10:08","date_gmt":"2018-01-02T15:10:08","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=243360"},"modified":"2018-01-02T17:10:44","modified_gmt":"2018-01-02T15:10:44","slug":"a-15-year-old-macos-security-flaw-allows-any-user-root-access","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/243360-a-15-year-old-macos-security-flaw-allows-any-user-root-access.html","title":{"rendered":"A 15 year-old MacOS security flaw allows any user root access"},"content":{"rendered":"<p>A &#8220;hobbyist hacker&#8221; who calls themselves Siguza on Twitter has posted the details of a security flaw in MacOS that allows any user on a machine to become the super administrator, or root, <strong><a href=\"https:\/\/wccftech.com\/15-year-old-macos-security-flaw-dumped-online\/\" target=\"_blank\" rel=\"noopener\">WccfTech reported<\/a><\/strong>.<\/p>\n<p>According to the report, the\u00a0bug is a local privilege escalation vulnerability in an extension of the macOS kernel called IOHIDFamily.<\/p>\n<p>The vulnerability lets an\u00a0attacker install a root shell or execute arbitrary code, and appears to be able to disable\u00a0System Integrity Protection and Apple Mobile File Integrity, which guard against malware.<\/p>\n<p>Siguza said that the flaw has been around for at least 15 years and all versions of MacOS are affected.<\/p>\n<p>Responding to criticism for not reaching out to Apple, the hacker explained that there is nothing to fear unless you are in a situation where an attacker might have physical access to your machine.<\/p>\n<p>They also said that Apple has been in contact with them and is working on a patch.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Yeah, I know. But they have actually been very few, and most of them seemed to be looking for a serious debate, so I&#39;m just trying to give them that. The overwhelming majority of responses have been positive, and Apple engineers themselves don&#39;t seem too sad about it&#8230;<\/p>\n<p>&mdash; @siguza@infosec.space (@s1guza) <a href=\"https:\/\/twitter.com\/s1guza\/status\/947696404536930310?ref_src=twsrc%5Etfw\">January 1, 2018<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/security\/240296-apple-releases-patch-for-macos-high-sierra-security-flaw.html\">Apple releases patch for macOS High Sierra security flaw<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>A &#8220;hobbyist hacker&#8221; who calls themselves Siguza on Twitter has posted the details of a security flaw in MacOS that allows any user on a machine to become the super administrator, or root.<\/p>\n","protected":false},"author":23,"featured_media":76168,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[605,36626,46601],"class_list":["post-243360","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-apple","tag-macos","tag-zero-day"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/243360"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=243360"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/243360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/76168"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=243360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=243360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=243360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}