Major macOS High Sierra Bug Allows Full Admin Access Without Password - How to Fix [Updated]

There appears to be a serious bug in macOS High Sierra that enables the root superuser on a Mac with a blank password and no security check.

The bug, discovered by developer Lemi Ergin, lets anyone log into an admin account using the username "root" with no password. This works when attempting to access an administrator's account on an unlocked Mac, and it also provides access at the login screen of a locked Mac.

rootbug
To replicate, follow these steps from any kind of Mac account, admin or guest:

1. Open System Preferences
2. Choose Users & Groups
3. Click the lock to make changes
4. Type "root" in the username field
5. Move the mouse to the Password field and click there, but leave it blank
6. Click unlock, and it should allow you full access to add a new administrator account.

At the login screen, you can also use the root trick to gain access to a Mac after the feature has been enabled in System Preferences. At the login screen, click "Other," and then enter "root" again with no password.

This allows for admin-level access directly from the locked login screen, with the account able to see everything on the computer.

It appears that this bug is present in the current version of macOS High Sierra, 10.13.1, and the macOS 10.13.2 beta that is in testing at the moment. It's not clear how such a significant bug got past Apple, but it's likely this is something that the company will immediately address.

Until the issue is fixed, you can enable a root account with a password to prevent the bug from working. We have a full how to with a complete rundown on the steps available here.

Update: An Apple spokesperson told MacRumors that a fix is in the works:

"We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the 'Change the root password' section."

Update 2: Apple released a security update to address the vulnerability on Wednesday morning. The update can be downloaded on all machines running macOS 10.3.1 using the Software Update mechanism in the Mac App Store. Apple says it will automatically push out the update to all users who have not installed it later in the day.

In a statement provided to MacRumors, Apple said the company's engineers began working on a fix as soon as the problem was discovered. Apple also apologized for the vulnerability and said its development process is being audited to prevent something similar from happening in the future.

Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.

When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

All users should download the new security update immediately.

Related Forum: macOS High Sierra

Popular Stories

apple oct 2024 mac tease

Apple Expected to Announce These Two to Three Products 'This Week'

Sunday October 12, 2025 7:05 am PDT by
Apple plans to announce new products "this week," according to Bloomberg's Mark Gurman. Apple's "Mac Your Calendars" teaser last October In his Power On newsletter today, Gurman said the products set to be updated this week include the iPad Pro, Vision Pro, and "likely" the base 14-inch MacBook Pro, with all three likely to receive a spec bump with Apple's next-generation M5 chip. Gurman...
10

Apple to Launch New Products Starting Next Week, Claims Dubious Leak [Updated]

Friday October 10, 2025 5:57 am PDT by
Update: the Naver account appears to be referencing a speculative post on X by Vadim Yuryev, dated October 6. The original article follows. Apple will announce new products through a series of press releases beginning as soon as next week, according to a dubious claim posted on the Korean blog Naver. The Naver blog account yeux1122, which aggregates rather than originates Apple...
iPhone 17 Pro Colors

iPhone 18 Pro Already Rumored to Have These 6 New Features

Saturday October 11, 2025 10:10 am PDT by
While the iPhone 18 Pro and iPhone 18 Pro Max are still nearly a year away, a handful of new features and changes have already been rumored for the devices. Below, we have recapped some of the early iPhone 18 Pro rumors so far. Smaller Dynamic Island The standard iPhone 18, iPhone 18 Pro, and iPhone 18 Pro Max will be equipped with a slightly smaller Dynamic Island, but the devices will...
iOS 26 Feature

Apple Preparing iOS 26.0.2 Update for iPhones

Saturday October 11, 2025 6:59 pm PDT by
Apple's software engineers are internally testing iOS 26.0.2, according to MacRumors logs, which have been a reliable indicator of upcoming iOS versions. iOS 26.0.2 will likely be a minor update that addresses bugs and/or security vulnerabilities, but we do not know any specific details yet. The update will likely be released within the next few weeks. Last month, Apple released iOS...
Tim Cook MacBook

Apple's Next CEO Identified

Wednesday October 8, 2025 12:30 pm PDT by
Apple's hardware engineering chief John Ternus remains the "leading contender" to become the company's next CEO, according to Bloomberg's Mark Gurman. Ternus is 50 years old, so he is still young enough to have a long run at the helm of Apple, after current CEO Tim Cook retires. He is already a key decision-maker at Apple, according to Gurman, and he appears to have a charismatic...
vivo liquid glass

iOS 26 Liquid Glass Design Copied by Android Smartphone Maker

Thursday October 9, 2025 4:07 pm PDT by
Chinese smartphone maker Vivo has taken some inspiration from Apple's Liquid Glass design language for its latest operating system update, OriginOS 6. Unveiled this week, OriginOS 6 has the same rounded buttons and translucent glass look as iOS 26. In a demo video, a Vivo smartphone features an interface that could be easily mistaken for iOS 26. There's a Liquid Glass clock, Control Center,...
10

Apple Event This October? Here's the Latest on What to Expect

Thursday October 9, 2025 7:00 am PDT by
While it is unclear if Apple will host an October event this year, or stick to press releases, rumors suggest it will announce several new products this month. The graphic for Apple's "Unleashed" event in October 2021 Below, we have recapped everything to know about a potential Apple event this October. When The table below outlines when Apple teased its October launches over the past...
apple invite colorado%402x

Apple Hosts Unusual Colorado Event to Showcase Latest Hardware

Thursday October 9, 2025 1:17 pm PDT by
Apple has invited a group of social media influencers to Colorado this week for an unusual event involving group hiking, trail running, and other outdoor activities designed to showcase the company's recently launched iPhone 17 Pro Max, AirPods Pro 3, and Apple Watch Ultra 3. An invitation was shared on X (Twitter) by photographer Johnny Hawk, featuring a simple message: "Hi Johnny. We're so ...
Apple MacBook Pro M4 hero

Apple Rumored to Launch MacBook Pro With M5 Chip Before M5 Pro and M5 Max Models

Friday October 10, 2025 1:18 pm PDT by
Apple is planning to release a base MacBook Pro with a standard M5 chip before higher-end models with M5 Pro and M5 Max chips, according to AppleInsider's sources with "knowledge of macOS Tahoe development and hardware testing." The report said a MacBook Pro with an M5 chip is "nearing release," and Apple has apparently been testing this model with an unreleased macOS 26.0.2 version....

Top Rated Comments

Quu Avatar
103 months ago
Honestly, what the hell Apple?
Score: 112 Votes (Like | Disagree)
Mr. Donahue Avatar
103 months ago
PUll it together Craig. You’re embarrassing yourself and Apple with iOS 11 and now this? What a shame.
Score: 82 Votes (Like | Disagree)
hamiltonDSi Avatar
103 months ago
10 years ago I started buying Apple products to avoid this kind of bugs.
Funny how things change :)

EDIT one day later :

Apple pushed an update with a fix under 24 hours, this is why i'm still using Apple products :)
Score: 71 Votes (Like | Disagree)
turbineseaplane Avatar
103 months ago
We need an "Even Higher Sierra" release, and only that, this coming year.

High Sierra is just stoned enough that she's letting everyone in...
Maybe if Sierra gets a bit higher, paranoia, and security concerns, might kick in.
Score: 53 Votes (Like | Disagree)
M.PaulCezanne Avatar
103 months ago
But emoji karaoke is working well on iPhone X. Whew!
Score: 52 Votes (Like | Disagree)
rpe33 Avatar
103 months ago
I am Root.
Score: 40 Votes (Like | Disagree)