Apple rushed out an emergency patch that fixed an bug in High Sierra that revealed APFS volume passwords via the password hint feature. The bug was one of two vulnerabilities addressed in the out-of-band fix. The other was a vulnerability disclosed shortly before the release of High Sierra last week that allowed attackers to dump plaintext passwords from the macOS keychain. Apple said the bug was addressed by clearing hint storage if the hint was the password, and by improving the logic for storing hints, Apple said in its advisory.
Source: https://threatpost.com/emergency-apple-patch-fixes-high-sierra-password-hint-leak/128314/

