macOS High Sierra's App Store System Preferences Can Be Unlocked With Any Password (macrumors.com)
A bug report submitted on Open Radar this week reveals a security vulnerability in the current version of macOS High Sierra that allows the App Store menu in System Preferences to be unlocked with any password. From a report: MacRumors is able to reproduce the issue on macOS High Sierra version 10.13.2, the latest public release of the operating system, on an administrator-level account by following these steps: 1. Click on System Preferences. 2. Click on App Store. 3. Click on the padlock icon to lock it if necessary. 4. Click on the padlock icon again. 5. Enter your username and any password. 6. Click Unlock.
As mentioned in the radar, System Preferences does not accept an incorrect password with a non-administrator account. We also weren't able to unlock any other System Preferences menus with an incorrect password. We're unable to reproduce the issue on the third or fourth betas of macOS High Sierra 10.13.3, suggesting Apple has fixed the security vulnerability in the upcoming release. However, the update currently remains in testing.
As mentioned in the radar, System Preferences does not accept an incorrect password with a non-administrator account. We also weren't able to unlock any other System Preferences menus with an incorrect password. We're unable to reproduce the issue on the third or fourth betas of macOS High Sierra 10.13.3, suggesting Apple has fixed the security vulnerability in the upcoming release. However, the update currently remains in testing.
in order to exploit this. Yeah, not really seeing the big deal.
...there seems to be a different auth code path for different padlock unlock/lock actions. Oh brother. So the bug isn't a big deal, but the symptom is troubling.
Yeah right.
Someone’s never been to a computer security conference...
This issue could be that you (the rightful admin level user) walks away from your computer to get another coffee and forget to lock it. While you're brewing, Mr Evil enters the scene and can unlock the App Store preferences panel without knowing your password.
Now I had a look at what is in this panel, there's not much that can be changed in there. The most "harmful" setting may be to save the store password for 15 minutes for purchasing apps.
Some other truly evil things that can be done in there is to change the checking of updates (Ooohhhh) - perhaps setting the "Automatically download apps purchased on other Macs" could be considered a DOS attack as it wouldn't take long to fill up the internal SSD with crap that you had downloaded over the years.
Anyway, it is bad that they have a password box that doesn't give a shit about what password you entered, but in this case not much damage can be done.
it is only after a long journey that you know the strength of the horse.
OK, this has somewhat limited potential, but still... what are they doing at Apple? Such things just should not happen. It's almost as if they're developing macOS as a hobby project, and there are hobby projects that do not have such glaring bugs.
Just wait for Amazon to patent the "one click login"