Skip to main content

Hacker discovers a MacOS exploit that is able to access system passwords

Security researcher Linus Henze recently uncovered a vulnerability within MacOS Mojave that allows an unauthorized application to steal passwords from both your Mac’s ‘login’ and ‘system’ Keychains. As macOS’ password management system, Keychain has been implemented since Mac OS 8.6, keeping user’s most important data safe and secure; however, as of late it doesn’t seem to be doing the job. A similar exploit was discovered and patched in 2017, but now Henze’s discovery, which he names KeySteal, is currently still within MacOS and available for hacker exploit.

KeySteal can access and view a system’s Keychains without requiring any permission from the user. Such action is typically protected by an administrator password needing to be entered before an application is granted access to a single part of the Keychain. The exploit itself needs to be launched when a user is logged in and could be extremely dangerous if unsuspectingly downloaded. The exploit completely bypasses security measures from Apple such as the company’s T2 security chip, and thus are entirely ineffective.

Henze’s KeySteal exploit has not been clearly explained from a technical level; he keeps the knowledge away from the public to prevent causing widespread security issues, but he has also held it from Apple. One point that has been routinely cited by MacOS security researchers is that Apple doesn’t offer a bounty for exploits as it does with its iOS platform. Thus, security researchers who spend their time discovering exploits are not rewarded for their work. It is common practice to pay security researchers for finding bugs and other exploits, putting Apple’s stance with MacOS in a unique position.

As of this moment, Apple has not commented on the exploit, nor has it issued a patch securing the vulnerability. Thus, users concerned about the KeySteal exploit should continue to follow safe security practices when downloading content from the web — not acquiring content from unknown sources and not running any applications that are unfamiliar. The previous exploit took Apple about two weeks to patch, but the researcher, Patrick Wardle, provided the company with detailed information, thus it is called into question how long it will take Apple to discover the current issue before offering the update.

Editors' Recommendations

Michael Archambault
Former Digital Trends Contributor
Michael Archambault is a technology writer and digital marketer located in Long Island, New York. For the past decade…
I never knew I needed this mini Mac app, but now I can’t live without it
Apple MacBook Pro 16 downward view showing keyboard and speaker.

Switching apps is something I do countless times every day on my Mac, so much so that I don’t ever think anything of it. That is until recently, when I discovered a new app that has me flipping windows in a new (and much-improved) way.

That app is called Quick Tab, and it’s designed to make app switching a little more painless. Now, I’ll admit that I’ve never thought of the traditional Command-Tab key combination as all that painful, but Quick Tab has swiftly shown me what I’ve been missing.

Read more
The MacBook Pro is a good enough gaming laptop for me
Halo running on a MacBook Pro.

I'm not a hardcore gamer. But like a lot of people, I like to dabble here and there. Looking at my limited Steam account, I find a handful of remotely current titles I've enjoyed lately, including Baldur's Gate 3 and Civilization VI.

When I fully converted to a MacBook Pro from Windows, I didn't expect to have even my limited gaming needs met. I figured it would just be something I'd lose in the transition. To my surprise, I've found myself quite enjoying the experience of gaming on my M3 Max MacBook Pro 16-inch. It won't be enough to satisfy gamers, but it was enough to get me excited for the future of gaming on the Mac.
Where the Metal meets the microchip

Read more
How to choose between a MacBook and a Windows laptop
The keyboard and trackpad of the MacBook Pro.

The MacBooks versus Windows laptops debate has been raging for decades, but never has it been this intense or important. New advances in chip technology are propelling even entry-level MacBooks to high-performance targets, and a shift in Windows laptops away from cheap plastics evens the playing field between these two platforms. Both Windows 11 and macOS are intuitive and clean operating systems. But where they differ comes down to one key element: their ecosystems.

What this means for you is that choosing an option from a list of the best laptops isn't so simple. The laptop you choose today can greatly influence which accessories you buy, which apps you use, and even what kind of phone you carry. Your entire workflow will depend on the platform you go with, from how you manage windows to which keyboard shortcuts work best. It's not a light decision.
Build quality vs. variety
The Dell XPS 14. Luke Larsen / Digital Trends

Read more