Apple updates High Sierra with fix for APFS Disk Utility flaw that revealed password instead of hint and Keychain vulnerability that let apps dump passwords
Apple today released a supplemental update to macOS High Sierra 10.13, the first update to the macOS High Sierra operating system …
Context & Ripple Effects
High Sierra debuted with Apple File System as part of a broader macOS release. This supplemental update puts security maintenance around that new storage layer and Keychain at the center of the rollout.
The later empty-password root access flaw and the upgrade that broke its patch show that this was not an isolated maintenance issue: High Sierra’s early security fixes became a reliability problem for Apple’s update process.
First-order effects
- High Sierra users receive fixes intended to stop Disk Utility from exposing passwords in place of hints and prevent apps from dumping Keychain passwords.
- Apple must distribute a supplemental update for vulnerabilities affecting two core macOS security surfaces: disk encryption administration and stored credentials.
Second-order effects
- Apps that could extract Keychain passwords lose that access after users install the update, while organizations managing High Sierra machines must treat patch installation as a credential-protection priority.
- Subsequent root-access failures raise the stakes for Apple’s remediation: the company later issued a critical root-vulnerability fix and said it was auditing its development processes.
Third-order effects
- The sequence points to security assurance becoming inseparable from operating-system rollout quality: a patch that fails to persist through an upgrade can undermine the value of a rapid fix.
- For Apple, repeated High Sierra credential and privilege issues create pressure to validate interactions among installers, upgrades, and core security tools rather than treating each flaw as a standalone defect.
The trend: High Sierra illustrates how major operating-system releases increasingly face scrutiny not only for new features but for the durability of their security-update pipeline.