macOS Big Sur 11.2.1 Fixes Root Access Sudo Bug

The macOS Big Sur 11.2.1 update that Apple released today fixes a sudo security vulnerability that could allow an attacker to gain root access to a Mac.

sudo bug macos
According to an Apple security support document, the bug, CVE-2021-3156, was addressed in the update by updating to sudo version 1.9.5p2. Apple has also fixed the bug in Supplemental Updates made available for macOS Catalina 10.15.7 and macOS Mojave 10.14.6.

The updates also include fixes for two bugs that could allow an app to execute arbitrary code with kernel privileges.

Discovered last week, the vulnerability triggers a "heap overflow" in sudo that changes the current user's privileges to enable root-level access, giving an attacker access to the entire system.

Popular Stories

iPhone 17 Slim Feature Single Camera 2

10 Reasons to Wait for Next Year's iPhone 17

Monday September 23, 2024 2:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different – already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
iPhone 15 Pro lineup

Apple's 80% Charging Limit for iPhone: How Much Did It Help After a Year?

Tuesday September 24, 2024 2:09 pm PDT by
With the iPhone 15 models that came out last year, Apple added an opt-in battery setting that limits maximum charge to 80 percent. The idea is that never charging the iPhone above 80 percent will increase battery longevity, so I kept my iPhone at that 80 percent limit from September 2023 to now, with no cheating. My iPhone 15 Pro Max battery level is currently at 94 percent with 299 cycles....
iPhone 17 Slim Feature Single Camera 2

iPhone 17 Air: Everything We Know About Apple's Slim iPhone

Monday September 23, 2024 1:50 am PDT by
In 2025, Apple is expected to discontinue the iPhone "Plus" device in its iPhone 17 lineup to make way for an iPhone "Air" – although it may not actually be called this when the device debuts in the fall of next year. Even though the iPhone 16 series has only just launched, when you consider that we learned about larger displays on the iPhone 16 Pro models way back in May 2023, rumors about a...
iphone 16 pro apple intelligence

Apple Intelligence Features Expected to Roll Out in This Order Between iOS 18.1 and iOS 18.4 [Updated]

Sunday September 22, 2024 6:00 am PDT by
iOS 18 was released to the public earlier this month, but the first Apple Intelligence features will not be available until iOS 18.1 is released in October. Apple Intelligence features will continue to roll out in iOS 18.2 and beyond, with the expected roadmap outlined below per Apple's website and rumors. Apple Intelligence requires an iPhone 15 Pro model or any iPhone 16 model, and it...
iFixit iPhone 16 Battery Removal

iPhone 16's 'Revolutionary' Battery Removal Process Shown in Video

Monday September 23, 2024 7:30 am PDT by
Over the weekend, well-known repair website iFixit shared an iPhone 16 and iPhone 16 Plus teardown video, and an accompanying blog post. Notably, the video shows Apple's new electrical battery removal process in action on the standard iPhone 16. iPhone 16 and iPhone 16 Plus batteries have an innovative type of adhesive that can be easily loosened with low-voltage electrical current, such as...

Top Rated Comments

neuropsychguy Avatar
47 months ago

Is Apple the first? Did other Unix and Linux push out the update too?
Most major Linux distros have already fixed it.

Examples:
https://ubuntu.com/security/CVE-2021-3156
https://access.redhat.com/security/cve/cve-2021-3156
https://www.suse.com/security/cve/CVE-2021-3156/
https://bodhi.fedoraproject.org/updates/FEDORA-2021-2cb63d912a
Score: 6 Votes (Like | Disagree)
luvbug Avatar
47 months ago
Thank you! Much more than a charging bug, for sure.
Score: 6 Votes (Like | Disagree)
TriBruin Avatar
47 months ago

Now if it could just come standard with allowing us to use TouchID instead of typing our password.
You know that you can enable this feature. Unfortunately, it has to be re-enabled after each update.

https://derflounder.wordpress.com/2017/11/17/enabling-touch-id-authorization-for-sudo-on-macos-high-sierra/
Score: 5 Votes (Like | Disagree)
ruka.snow Avatar
47 months ago
Fantastic. Unlikely to affect me but still good to have the furniture nailed down.
Score: 4 Votes (Like | Disagree)
Jerry Fritschle Avatar
47 months ago

Reminds me of High Sierra. Waiting for the login “root” user access now. :p
I admit I thought of that, too. However, "sudo" is a utility found throughout unix/Linux systems. This was therefore not an "Apple" bug, but rather an update that had to come from upstream :-)
Score: 3 Votes (Like | Disagree)
Rafterman Avatar
47 months ago
Thanks Apple for yet another reboot. Get it right the first time.
Score: 2 Votes (Like | Disagree)