A zero day exploit was just announced for the MacOS High Sierra which allows theft of passwords in plain text from an unsigned app, without entering a password. Apparently, earlier versions are also vulnerable.
Apple gave a statement which suggests that users should not download unsigned apps.
He reported the bug to Apple earlier this month, "but unfortunately the patch didn't make it into High Sierra," he said, which was released Monday. MacOS High Sierra Zero Day Vulnerability [zdnet.com]