A recent bug in the Sudo application that was found to affect Linux and BSD operating systems also appears to affect macOS, a security researcher from Britain has discovered

The vulnerability, discovered last week by security researchers at Qualys and dubbed CVE-2021-3156, affects the Sudo application, which allows administrators to grant limited root access to other users.
Qualys researchers discovered that they could exploit “heap overflow” bugs in the Sudo application to change the current user’s access from low-privileged to root level, giving the attacker access to the entire system.
The only requirement for exploiting this bug was for an attacker to gain access to a system, which the researchers said could be done either by placing malware on a device or by brute-forcing low-priviledged accounts.
Qualys researchers said in a report on the bug that they only tested the exploit on Ubuntu, Debian , and Fedora. They said that UNIX-like operating systems are also affected, but most security researchers believed that the bug could also affect BSD, another major operating system that also ships with the Sudo application.

However, as Matthew Hickey , the co-founder of Hacker House , pointed out on Twitter , the latest version of macOS also supports the Sudo application.
Hickey said he tested the CVE-2021-3156 vulnerability and found that with a few modifications, it could be used to grant attackers access to macOS root accounts as well.
"To enable it, you simply need to replace argv[0] or create a symlink, which exposes the operating system to the same root vulnerability that hit Linux users last week," Hickey said, sharing a video of the bug in question.
His findings were also verified and confirmed by Patrick Wardle, one of today's leading macOS security experts, and publicly by Will Dormann, a vulnerability analyst at Carnegie Mellon.
Hickey said the flaw could be exploited in the latest version of macOS, even after applying the latest security updates released by Apple on Monday.
The researcher said he notified Apple of the issue. Apple declined to comment as it investigates the incident. However, even without official confirmation from the company, a patch for such a serious issue is likely expected. Additionally, other researchers have found that the flaw could also be exploited on IBM AIX.
