OS X Vulnerability Can Allow Superuser Access to Unauthorized Users - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

OS X Vulnerability Can Allow Superuser Access to Unauthorized Users

FilevaultUsers looking to exploit a vulnerability in the Sudo Unix command, originally reported back in March, have received some assistance, reports Ars Technica.

The developers of Metasploit, software that makes it easier to misuse vulnerabilities in operating systems and applications, have added the Sudo vulnerability to their software suite. All versions of OS X from OS X Lion 10.7 through the current Mountain Lion 10.8.4 remain vulnerable.

Mac users should realize that an attacker must satisfy a variety of conditions before being able to exploit this vulnerability. For one, the end-user who is logged in must already have administrator privileges. And for another, the user must have successfully run sudo at least once in the past. And of course, the attacker must already have either physical or remote shell access to the target machine. In other words: this exploit can't be used in the kind of drive-by webpage attacks that last year infected some 650,000 Macs with the Flashback malware. This doesn't mean it's a non-issue though, since the exploit can be used in concert with other attacks to magnify the damage they can do.

Most of the recent exploits in Mac OS X have been related to Java, which Apple completely blocked earlier this year over security vulnerabilities, though Apple did release a standalone malware removal tool to help clean machines that were affected by a number of Java vulnerabilities.

OS X has been targeted more in recent years as it has gained in popularity. The Janicab.A malware was discovered last month, while another program called macs.app was discovered in May. That app captured and stored screenshots.

Popular Stories

Home Hub Command Center with Dome Base Feature

Apple Smart Home Hub to Feature iMac G4-Style Design

Wednesday September 30, 2026 4:36 am PDT by
Apple's long-rumored smart home hub will have an iMac G4-style design and a host of unique features, Bloomberg's Mark Gurman reports. The smart home hub is said to feature a square 6-inch display, with variants that can be placed on a countertop or mounted on a wall. It features a single FaceTime camera on the front, with microphones and speakers in its connected base. Gurman described the...
HomePod minis on gradient feature 1 1

Three New Apple Smart Home Products Coming on October 13

Wednesday September 30, 2026 4:04 am PDT by
Apple plans to introduce a series of new smart home products on Tuesday, October 13, according to Bloomberg's Mark Gurman. Apple reportedly plans to debut its long-awaited smart home hub device, a new HomePod mini, and a new Apple TV on the date. The new HomePod mini and Apple TV are set to retain their existing designs, but tout faster chips to support Siri AI. The new HomePod mini will...
Apple TV Sans Remote Feature

New Apple TV 4K Leaked

Friday September 25, 2026 8:16 am PDT by
MacRumors contributor Aaron Perris has uncovered an image file from Apple for an unreleased Apple TV 4K, suggesting that a new model will finally be released soon. The image is specifically for an "Apple TV 4K (4th generation)" model. Apple TV 4K (4th generation) image (on a gradient) The image reveals that the Apple TV will have the same external design as the current model, with all of its...

Top Rated Comments

171 months ago
Since this is a "flaw" (to the extent it has been described) in sudo, it's not Mac-specific. Other flavors of UNIX are also affected. But it's more fun and gets more hits and attention when you call it an "OS X Vulnerability", as if it's Apple's mistake or fault and not due to an issue (if that's what it is) in one of several hundred non-Apple projects (http://www.sudo.ws).
Score: 10 Votes (Like | Disagree)
sjinsjca Avatar
171 months ago
"I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.

Admin != root
Score: 8 Votes (Like | Disagree)
171 months ago
I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.
Admin and root are two different levels of access. You can do some things with root that you cannot do with admin. Root is the deepest access one can have - but it's not really the goal of most hackers. An administrator account is probably the most that an attacker really needs since they can pretty much do anything they need with that account.

So an exploit that needs admin rights access and one that rehires you to have used sudo isn't one that is high priority. The number of users that run sudo at all is really small, and from a security standpoint, if you have admin rights, all security goes out the window. In other words, you don't have security.
Score: 8 Votes (Like | Disagree)
mikethebigo Avatar
171 months ago
Sudo make me a sandwich.
Score: 6 Votes (Like | Disagree)
171 months ago
You don't need to run metasploit to exploit this bug.

The following command should give you root if you are logged in to OS X as an Administrator and have used the "sudo" command at least once in the past. It will also set your system clock to 01/01/1970.

sudo -k
systemsetup -setusingnetworktime Off -settimezone GMT -setdate 01:01:1970 -settime 00:00
sudo su

To set your system clock back to normal, go into the System Preferences and set the time and time zone back to the way it was.

To prevent somebody from abusing this attack, you will need to run the following command after every time you use the sudo command, until it gets patched.
sudo -K
Score: 6 Votes (Like | Disagree)
Dalton63841 Avatar
171 months ago
"For one, the end-user who is logged in must already have administrator privileges. And for another, the user must have successfully run sudo at least once in the past."

I'm not too sure why a user who already has admin access would bother using an exploit to gain admin privilege - an access level he already has.
What it is saying is that if an attacker already has access to your machine, AND you are on an administrator account, AND you have opened Terminal and used sudo, THEN they could maybe gain root access to your account.
Score: 6 Votes (Like | Disagree)
Latest Stories
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
1 hour ago
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
2 hours ago
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
2 hours ago
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
3 hours ago
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
3 hours ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
14 hours ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
15 hours ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
19 hours ago
Apple Event on October 13?
Apple Event on October 13?
20 hours ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
22 hours ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
22 hours ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
23 hours ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
23 hours ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
1 day ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
1 day ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
1 day ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
1 day ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
2 days ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
2 days ago
AirPods 5 Teardown: Batteries Removable, Case Still Tough
AirPods 5 Teardown: Batteries Removable, Case Still Tough
2 days ago
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
2 days ago
You Can 'Get Ready' for iPhone Duo Pre-Orders on October 12
You Can 'Get Ready' for iPhone Duo Pre-Orders on October 12
2 days ago
Apple Pay Reportedly Launching in India Today
Apple Pay Reportedly Launching in India Today
2 days ago
Apple Releases New AirPods Beta Firmware
Apple Releases New AirPods Beta Firmware
2 days ago
Apple Shares New Guide for Using iOS 27 Parental Controls
Apple Shares New Guide for Using iOS 27 Parental Controls
2 days ago
Apple Creator Studio and Final Cut Camera Get New Features
Apple Creator Studio and Final Cut Camera Get New Features
2 days ago
Apple Explains Why It Removed ICE Tracking Apps Last Year
Apple Explains Why It Removed ICE Tracking Apps Last Year
2 days ago
Amazon Expands $779.99 Apple Watch Ultra 4 Deal to More Models
Amazon Expands $779.99 Apple Watch Ultra 4 Deal to More Models
2 days ago
Switch Siri AI for ChatGPT on Your Mac
Switch Siri AI for ChatGPT on Your Mac
2 days ago
Apple Says Emergency SOS via Satellite Now Available in Norway
Apple Says Emergency SOS via Satellite Now Available in Norway
2 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors