	{"id":57445,"date":"2016-09-21T09:43:24","date_gmt":"2016-09-21T16:43:24","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=57445"},"modified":"2016-12-20T10:28:57","modified_gmt":"2016-12-20T18:28:57","slug":"macos-sierra-10-12-vulnerability-fixes-and-security-enhancements","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/","title":{"rendered":"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-57517\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Security-Update.jpg\" alt=\"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Security-Update.jpg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Security-Update-150x75.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Security-Update-300x150.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some tweaks to the operating system\u00a0itself to improve\u00a0security as well. A separate Safari 10 update was also released, which fixes 21 vulnerabilities, and is included with macOS Sierra 10.12.<\/p>\n<p>As an added bonus, the list of <a href=\"https:\/\/support.apple.com\/en-us\/HT207157\" target=\"_blank\" rel=\"nofollow\">vulnerability fixes in iOS 10<\/a> was amended to show 28 additional vulnerabilities that were addressed in the release. Apple did not release these details until Sierra was released, likely because both operating systems shared the same flaws. Publishing details on the flaws that were addressed in iOS 10 would have given those with malicious intent a nice roadmap of what to exploit in OS X.<\/p>\n<h3>Vulnerabilities Patched in macOS Sierra<\/h3>\n<ul>\n<li><strong>apache_mod_php<\/strong> &#8211; Allows Apache to interpret PFP files. This module received 16 fixes that were addressed by updating the PHP version to 5.6.24 to avoid arbitrary code execution.<\/li>\n<li><strong>Application Firewall<\/strong> &#8211; The firewall in your System Preferences &gt; Security &amp; Privacy pane. A local user may have been able to cause a denial of service so this was addressed to make sure it won&#8217;t happen again.<\/li>\n<li><strong>ATS<\/strong> &#8211; Stands for Apple Type Services which\u00a0handles fonts on your Mac. Processing a maliciously crafted font file may have lead to arbitrary code execution. This was addressed by improving memory handling.<\/li>\n<li><strong>Bluetooth<\/strong>\u00a0&#8211; A memory corruption was addressed to prevent an application from executing arbitrary code with kernel privileges.<\/li>\n<li><strong>CoreCrypto<\/strong> &#8211; Provides implementations of low level cryptographic primitives. Vulnerable code was removed to avoid applications being able to execute arbitrary code.<\/li>\n<li><strong>CoreDisplay<\/strong> &#8211;\u00a0A user with screen sharing access may have been able to view another user&#8217;s screen. Fixed by the improvement of session tracking.<\/li>\n<li><strong>Date &amp; Time Pref Pane<\/strong> &#8211;\u00a0A malicious application may have been able to determine a user&#8217;s current location. Fixed by the improvement of validation.<\/li>\n<\/ul>\n<p>There are many more entries <a href=\"https:\/\/support.apple.com\/en-us\/HT207170\" target=\"_blank\" rel=\"nofollow\">on the list<\/a>, but the trend is arbitrary code execution. In plain english, someone can run code on your Mac and give it commands to do something it should not be doing. Something you don&#8217;t want. This is why installing Mac OS upgrades and Security Updates is always a good idea. It&#8217;s nice of Apple to list all the vulnerabilities that were addressed, but this also, as mentioned earlier, gives someone with malicious intent a good idea of what to exploit on systems that are not updated.<\/p>\n<p>For those not familiar with reading <a href=\"https:\/\/support.apple.com\/en-us\/HT207170\" target=\"_blank\">Apple Security bulletins<\/a>, the addressed vulnerabilities mention &#8220;Available for: OS X El Capitan v10.11.6,&#8221; but this means the vulnerability was <span style=\"text-decoration: underline\">found<\/span> in OS X El Capitan and fixed <span style=\"text-decoration: underline\">only<\/span> if you update to macOS Sierra. The wording can make someone believe the fix applies to El Capitan as well. El Capitan itself did not receive any security updates, but will likely see some released alongside future Sierra updates (10.12.1, 10.12.2, and so forth) to cover some critical vulnerabilities.<\/p>\n<p>Security was also implemented in the form of new features.<\/p>\n<h3>New Security Features in macOS Sierra<\/h3>\n<p><strong>Gatekeeper<\/strong><\/p>\n<p>The option to allow unsigned applications has been removed from the System Preferences &gt; Security &amp; Privacy pane.<\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Gatekeeper.gif\"><img loading=\"lazy\" class=\" wp-image-57448 size-full aligncenter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macOS-Sierra-Gatekeeper.gif\" alt=\"\" width=\"630\" height=\"138\" \/><\/a><\/p>\n<p>You can still get unsigned applications to open via other means, but this prevents unskilled users from\u00a0accidentally (or intentionally, without realizing the possible consequences) set the &#8220;Anywhere&#8221; option.<\/p>\n<p>Another new Gatekeeper feature is called Path Randomization. This feature is designed to prevent repackaging attacks or &#8220;<a href=\"https:\/\/papers.put.as\/papers\/macosx\/2015\/vb201503-dylib-hijacking.pdf\" target=\"_blank\" rel=\"nofollow\">dynamic library hijacks<\/a>&#8221; (PDF), where a legit app can be tricked into loading malicious contents. Now an application is taken from its current location, placed in a random location on your Mac&#8217;s hard drive and executed from there. This way the application does not have access to potentially hidden and malicious resources that came in the container. dmg, zip and ISO files are\u00a0good examples of such a container.<\/p>\n<p><strong>Differential Privacy<\/strong><\/p>\n<p>As the name implies, this is more a privacy feature than a security feature, but a nice one nevertheless. Basically this allows Apple to collect usage patterns that can help them improve products and services, without compromising individual privacy. This is done using machine learning and artificial intelligence on your Mac, so only anonymized usage statistics are sent to Apple. Helping Apple to improve their products will ultimately benefit us as users and now we get to do it while keeping our privacy.<\/p>\n<p><strong>Auto Unlock<\/strong><\/p>\n<p>Your Mac will unlock when you walk up to it and it will lock when you walk away \u2014 simply by wearing your Apple Watch.<\/p>\n<p><strong>Weak cipher suite removed<\/strong><\/p>\n<p>The RC4 cipher is a stream that&#8217;s used to negotiate an encryption between your browser and the website you visit.\u00a0Several exploits are known that make the RC4 cipher insecure and no longer trusted, so Apple dropped it. The same goes for SSLv3, a cryptographic protocol that was <a href=\"https:\/\/security.googleblog.com\/2014\/10\/this-poodle-bites-exploiting-ssl-30.html\" target=\"_blank\" rel=\"nofollow\">found to be vulnerable<\/a>.<\/p>\n<h3>Safari 10<\/h3>\n<p><strong>Apple Pay on the web<\/strong><\/p>\n<p>Use your TouchID enabled iOS device or Apple Watch to pay online.\u00a0With Apple Pay, your credit card number is not being stored or shared and transaction information is not kept\u00a0\u2014 overall a faster and more secure process. For more information about Apple Pay, <a href=\"https:\/\/www.apple.com\/apple-pay\/\" target=\"_blank\" rel=\"nofollow\">have a look here<\/a>.<\/p>\n<p><strong>Web plugins disabled by default<\/strong><\/p>\n<p>Adobe Flash Player, Java and other plug-ins that can be exploited\u00a0to load malicious content on your Mac are now disabled by default, but can be clicked by the user to activate.<\/p>\n<p>Intego&#8217;s Mac security software\u00a0<a href=\"https:\/\/www.intego.com\/mac-security-blog\/intego-software-updated-for-macos-sierra-compatibility\/\">has been updated<\/a> to be fully compatible with macOS Sierra as well.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some tweaks to the operating system\u00a0itself to improve\u00a0security as well. A separate Safari 10 update was also released, which fixes 21 vulnerabilities, and is included with macOS Sierra 10.12. As an [&hellip;]<\/p>\n","protected":false},"author":79,"featured_media":57523,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[151,13,5],"tags":[3151,174,3058,3127,2998,143],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2016-09-21T16:43:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-12-20T18:28:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jay Vrijenhoek\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg\",\"width\":400,\"height\":260,\"caption\":\"macOS Sierra Security Enhancements\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/\",\"name\":\"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage\"},\"datePublished\":\"2016-09-21T16:43:24+00:00\",\"dateModified\":\"2016-12-20T18:28:57+00:00\",\"description\":\"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\"},\"headline\":\"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements\",\"datePublished\":\"2016-09-21T16:43:24+00:00\",\"dateModified\":\"2016-12-20T18:28:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage\"},\"wordCount\":918,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg\",\"keywords\":[\"Apple\",\"Mac\",\"macOS Sierra\",\"macOS Sierra 10.12\",\"OS X El Capitan 10.11.6\",\"Vulnerabilities\"],\"articleSection\":[\"Recommended\",\"Security &amp; Privacy\",\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0\",\"name\":\"Jay Vrijenhoek\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g\",\"caption\":\"Jay Vrijenhoek\"},\"description\":\"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/","og_locale":"en_US","og_type":"article","og_title":"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements - The Mac Security Blog","og_description":"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some","og_url":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/","og_site_name":"The Mac Security Blog","article_published_time":"2016-09-21T16:43:24+00:00","article_modified_time":"2016-12-20T18:28:57+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jay Vrijenhoek","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg","width":400,"height":260,"caption":"macOS Sierra Security Enhancements"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/","name":"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage"},"datePublished":"2016-09-21T16:43:24+00:00","dateModified":"2016-12-20T18:28:57+00:00","description":"This week Apple released macOS Sierra to the public and, apart from some nice new features, it includes fixes for 65 security vulnerabilities and some","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0"},"headline":"macOS Sierra 10.12: Vulnerability Fixes and Security Enhancements","datePublished":"2016-09-21T16:43:24+00:00","dateModified":"2016-12-20T18:28:57+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#webpage"},"wordCount":918,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg","keywords":["Apple","Mac","macOS Sierra","macOS Sierra 10.12","OS X El Capitan 10.11.6","Vulnerabilities"],"articleSection":["Recommended","Security &amp; Privacy","Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/macos-sierra-10-12-vulnerability-fixes-and-security-enhancements\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/0106660ab83668e429deecc051dfa8c0","name":"Jay Vrijenhoek","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8f43effd03d0bb31acff4b88613f0d4a?s=96&d=mm&r=g","caption":"Jay Vrijenhoek"},"description":"Jay Vrijenhoek is an IT consultant with a passion for Mac security research.","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/jay-vrijenhoek\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/09\/macos-sierra-security-enhacements.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-eWx","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/57445"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/79"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=57445"}],"version-history":[{"count":25,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/57445\/revisions"}],"predecessor-version":[{"id":60388,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/57445\/revisions\/60388"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/57523"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=57445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=57445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=57445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}