Friday, September 15, 2006

How a Malformed Installer Package Can Crack Mac OS X

There exists a pretty significant interface problem with the Apple Installer program such that any package requesting admin access via the AdminAuthorization key, when run in an admin user account, is given full root-level access without providing the user with a password prompt during the install.

You can read more about it here.

No comments: