This site uses cookies, tokens, and other third party scripts to recognize visitors of our sites and services, remember your settings and privacy choices, and — depending on your settings and privacy choices — enable us and some key partners to collect information about you so that we can improve our services and deliver relevant ads.

By continuing to use our site or clicking Accept, you agree that CBS and our key partners may collect data and use cookies for personalized ads and other purposes, as described more fully in our privacy policy. You can change your settings at any time by clicking Manage Settings.

just in Supreme Court says police need a warrant for cell location records

Apple fixes two High Sierra password bugs

It's the first update for the new Mac operating system since it was released last month.

(Image: CNET/CBS Interactive)

Apple has fixed two vulnerabilities in its Mac operating system that put passwords at risk of theft by hackers.

The company released the security fix Thursday, an Apple spokesperson told ZDNet.

Synack's Patrick Wardle, who was credited with finding one of the now-fixed vulnerabilities, revealed a password-stealing bug just hours before High Sierra was released.

The bug let an attacker grab and steal every password in plain text using a malicious, unsigned app downloaded from the internet -- without needing the user's master Keychain password.

Apple fixed the bug by requiring users to enter their password before unlocking their Keychain.

Thursday's security update also fixed another security vulnerability affecting encrypted volumes using Apple's new file system, APFS, in which the volume's password was stored as the password hint and could be revealed in plain text.

Apple acknowledged Matheus Mariano for finding the bug.