Apple to audit development processes after Mac bug discovered

Uber lawyer says ex-CEO, board members told of letter kept from Waymo lawsuit
November 29, 2017
Bubble trouble? Bitcoin tops $11,000, but fades after sharp rally
November 29, 2017
This post was originally published on this site

(Reuters) – Apple Inc (AAPL.O) said on Wednesday it would review its software development process a day after a researcher discovered a bug in a new version of its Mac operating system that could give hackers total control of vulnerable machines.

FILE PHOTO – A guest points to a new MacBook Pro during an Apple media event in Cupertino, California, U.S. October 27, 2016. REUTERS/Beck Diefenbach

Apple said it released a patch to fix the bug on Wednesday morning and it would be automatically installed on vulnerable machines later in the day.

“We greatly regret this error and we apologize to all Mac users,” Apple said in a statement. “Our customers deserve better. We are auditing our development processes to help prevent this from happening again.”

To exploit the bug, a hacker would need to have physical access to a vulnerable Mac when a user is logged on to the computer. The attacker would then need to change settings on the computer to establish a “root” account, which they could later access.

Root accounts give users complete control over a machine.

The U.S. and German governments issued alerts advising Mac users to install the patch.

Apple said its security engineers learned of the problem on Tuesday afternoon and posted the patch within 24 hours.

“Security is a top priority for every Apple product, and regrettably we stumbled with this release of Mac OS,” Apple said in its statement.

Apple stock was down 2.6 percent at $168.55 on Wednesday during a broad selloff in tech stocks.

The behavior in the Mac operating system that led to the bug’s discovery was described by developers on an Apple forum as early as Nov. 13 as a workaround for problem accessing administrator accounts.

Reporting by Stephen Nellis in San Francisco and Dougl Busvine in Frankfurt; Editing by Jim Finkle and Andrew Hay

Our Standards:The Thomson Reuters Trust Principles.