Skip to main content

Hacker discovers a MacOS exploit that is able to access system passwords

Security researcher Linus Henze recently uncovered a vulnerability within MacOS Mojave that allows an unauthorized application to steal passwords from both your Mac’s ‘login’ and ‘system’ Keychains. As macOS’ password management system, Keychain has been implemented since Mac OS 8.6, keeping user’s most important data safe and secure; however, as of late it doesn’t seem to be doing the job. A similar exploit was discovered and patched in 2017, but now Henze’s discovery, which he names KeySteal, is currently still within MacOS and available for hacker exploit.

KeySteal can access and view a system’s Keychains without requiring any permission from the user. Such action is typically protected by an administrator password needing to be entered before an application is granted access to a single part of the Keychain. The exploit itself needs to be launched when a user is logged in and could be extremely dangerous if unsuspectingly downloaded. The exploit completely bypasses security measures from Apple such as the company’s T2 security chip, and thus are entirely ineffective.

Recommended Videos

Henze’s KeySteal exploit has not been clearly explained from a technical level; he keeps the knowledge away from the public to prevent causing widespread security issues, but he has also held it from Apple. One point that has been routinely cited by MacOS security researchers is that Apple doesn’t offer a bounty for exploits as it does with its iOS platform. Thus, security researchers who spend their time discovering exploits are not rewarded for their work. It is common practice to pay security researchers for finding bugs and other exploits, putting Apple’s stance with MacOS in a unique position.

As of this moment, Apple has not commented on the exploit, nor has it issued a patch securing the vulnerability. Thus, users concerned about the KeySteal exploit should continue to follow safe security practices when downloading content from the web — not acquiring content from unknown sources and not running any applications that are unfamiliar. The previous exploit took Apple about two weeks to patch, but the researcher, Patrick Wardle, provided the company with detailed information, thus it is called into question how long it will take Apple to discover the current issue before offering the update.

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
macOS 16: everything you need to know
macos update everything you need to know craig federighi ventura wwdc 2023

Apple's Worldwide Developers Conference (WWDC 2025) date has been set for June 9, 2025, and the next macOS installment will be one of the main attractions. Excitement is already building for this year's installment thanks to rumors of a major design overhaul for the Mac operating system. This is everything we've heard so far about macOS 16.
When will macOS 16 launch?

In recent years, Apple has developed a neat little schedule for WWDC, announcements, and product releases. As we now know that WWDC will take place on June 9, it's highly likely that macOS 16 will be announced on that day. The keynote will introduce all of the biggest new features, updates, and products, making it the most exciting part of the conference for most of us.

Read more
Latest Apple OS land in beta, these are all the new features to try
Apple OS beta

Apple has taken the wraps off its latest operating systems for beta testing, meaning some exciting new features are available.

The new systems run across Apple devices with the arrival of iOS 18.4, macOS 15.4, watchOS 11.4, iPadOS 18.4, tvOS 18.4, and visionOS 2.4 all now available in RC.

Read more
Mac users are being targeted by a vicious new phishing scam. Here’s how to stay safe
A hacker typing on an Apple MacBook laptop, which shows code on its screen.

There’s a well-known myth that Macs are somehow invulnerable to viruses, phishing attempts, hackers and the like. You might have heard it before, or maybe you even believe it yourself. Unfortunately, it’s far from true. Because while Windows users face more threats than their Mac counterparts, that doesn’t mean that Mac users should get complacent.

That point has just been perfectly illustrated by a new phishing scam that is specifically targeting Macs. It’s so advanced, in fact, that LayerX Security, the firm that has been tracking the attack, has said that similar campaigns “have rarely reached this level of sophistication.”

Read more