Blog | G5 Cyber Security

Unsigned apps can dump the full OS keychain, including your plaintext passwords

Hackers can steal macOS keychain passwords using unsigned applications, it works on the latest version of macOS, High Sierra 10.13, and previous releases. The attack does not require the knowledge of the master password, it only needs the targeted user to download and launch a malicious application, ignoring warnings displayed when an app from an unidentified developer is being executed. By default the keychain is unlocked when the user logs in, but you can change the password (so it is not automatically unlocked during login, or lock it while not using it.”]

Source: https://securityaffairs.co/wordpress/63439/hacking/os-keychain-data-theft.html

Exit mobile version