Reverse engineering the macOS High Sierra supplemental update

Reported by Matheus Mariano, a Brazilian software developer, a programming error was discovered in Apple’s most recent operating system, High Sierra, that exposed passwords of encrypted volumes as password hints. A serious bug that quickly made the headlines in technology websites everywhere.

Apple was prompt to provide macOS High Sierra Supplemental Update to customers via the App Store, and ensured that every distribution of High Sierra in their servers included this update.

I decided to apply a binary diffing technique to the update to learn more about the root cause of this bug and hypothesize about how the defect could have been prevented.


  1. 2017-10-10 8:50 am
    • 2017-10-10 5:53 pm
    • 2017-10-11 11:29 am
      • 2017-10-14 1:31 pm
  2. 2017-10-10 5:28 pm
    • 2017-10-13 8:47 am