Anyone can hack your Mac unless you patch it now — here's how

MacBook Pro 2021 leaks
(Image credit: Vito Corleone/SOPA Images/LightRocket via Getty Images)

Apple has fixed a severe security flaw that threatened all supported versions of macOS, one week after the flaw was publicly disclosed.

The vulnerability, detailed in our report on February 3, permits full system takeover by remote attackers or malware. The attackers or malware would have to first use other methods to first gain access to a Mac, but that's not as hard as it sounds. 

To update your Mac, click the Apple icon at the top left of your desktop screen and select System Preferences from the drop-down menu. Then click the Software Update icon in the selection screen. You may also get notifications that a new update is available.

After the update is finished, you should be running macOS Big Sur 11.2.1, macOS Catalina 10.15.7 or macOS Mojave 10.14.6. If you're running macOS High Sierra 10.13 or earlier, it's time to upgrade to a newer version of macOS because the older versions aren't fixing this very serious flaw.

Beating back the Baron

The vulnerability, called "Baron Samedit" by its discoverers, has to do with the "sudo" command found on almost all Unix-derived operating systems, including macOS and Linux. 

Sudo temporarily gives full system access, or "root," to users who already have administrative privileges. With root, a user can make almost any change to the operating system, which is why even admin users don't normally have such powers. Regular users without admin privileges normally can't access sudo.

Baron Samedit, first disclosed on Linux in late January, gets around this privileges hierarchy. It lets any user, even one without admin rights, gain root without using an admin password. Because of this, an email attachment or a web link opened by a non-admin user could end up taking over a machine. 

The major Linux distributions fixed the vulnerability before it was publicly revealed. But while it initially looked like macOS might be immune to the Baron Samedit flaw, a security researcher soon found an easy workaround that made exploiting the flaw possible on Macs.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours