Security bug in macOS authorization plugin

Hi,

A user logs in to the file vault, and DisableFDEAutoLogin is false. The file vault login succeeds, but the login to the selected user fails. The user gets the login screen again. If the user puts an invalid password to try and login again, the loginwindow:FDESupport plugin will change the user's password to the invalid one.

Answered by DTS Engineer in 858956022

If your goal is to report a bug, you should do that using Feedback Assistant. See Bug Reporting: How and Why? for detailed advice on how to file effective bug reports.

Please post your bug number, just for the record.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

If your goal is to report a bug, you should do that using Feedback Assistant. See Bug Reporting: How and Why? for detailed advice on how to file effective bug reports.

Please post your bug number, just for the record.

Share and Enjoy

Quinn “The Eskimo!” @ Developer Technical Support @ Apple
let myEmail = "eskimo" + "1" + "@" + "apple.com"

Security bug in macOS authorization plugin
 
 
Q