Earlier today, Apple has issued an
emergency update for macOS High Sierra to address a bug that exposed the passwords of encrypted APFS volumes via the password hint feature.
The bug was discovered earlier today by Brazilian security researcher Matheus Mariano of Leet Tech, who also published the YouTube video embedded below.
The issue occurs only on macOS High Sierra when users add a new encrypted APFS volume to their container.
When the user mounts the APFS volume and is asked to enter the password before being able to access the data, if the user presses the password hint button, the user's password is displayed instead of the the hint.