Major macOS High Sierra Bug Allows Full Admin Access Without Password - How to Fix [Updated]

There appears to be a serious bug in macOS High Sierra that enables the root superuser on a Mac with a blank password and no security check.

The bug, discovered by developer Lemi Ergin, lets anyone log into an admin account using the username "root" with no password. This works when attempting to access an administrator's account on an unlocked Mac, and it also provides access at the login screen of a locked Mac.

rootbug
To replicate, follow these steps from any kind of Mac account, admin or guest:

1. Open System Preferences
2. Choose Users & Groups
3. Click the lock to make changes
4. Type "root" in the username field
5. Move the mouse to the Password field and click there, but leave it blank
6. Click unlock, and it should allow you full access to add a new administrator account.

At the login screen, you can also use the root trick to gain access to a Mac after the feature has been enabled in System Preferences. At the login screen, click "Other," and then enter "root" again with no password.

This allows for admin-level access directly from the locked login screen, with the account able to see everything on the computer.

It appears that this bug is present in the current version of macOS High Sierra, 10.13.1, and the macOS 10.13.2 beta that is in testing at the moment. It's not clear how such a significant bug got past Apple, but it's likely this is something that the company will immediately address.

Until the issue is fixed, you can enable a root account with a password to prevent the bug from working. We have a full how to with a complete rundown on the steps available here.

Update: An Apple spokesperson told MacRumors that a fix is in the works:

"We are working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here: https://support.apple.com/en-us/HT204012. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the 'Change the root password' section."

Update 2: Apple released a security update to address the vulnerability on Wednesday morning. The update can be downloaded on all machines running macOS 10.3.1 using the Software Update mechanism in the Mac App Store. Apple says it will automatically push out the update to all users who have not installed it later in the day.

In a statement provided to MacRumors, Apple said the company's engineers began working on a fix as soon as the problem was discovered. Apple also apologized for the vulnerability and said its development process is being audited to prevent something similar from happening in the future.

Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.

When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

All users should download the new security update immediately.

Top Rated Comments

Quu Avatar
57 months ago
Honestly, what the hell Apple?
Score: 112 Votes (Like | Disagree)
Mr. Donahue Avatar
57 months ago
PUll it together Craig. You’re embarrassing yourself and Apple with iOS 11 and now this? What a shame.
Score: 82 Votes (Like | Disagree)
hamiltonDSi Avatar
57 months ago
10 years ago I started buying Apple products to avoid this kind of bugs.
Funny how things change :)

EDIT one day later :

Apple pushed an update with a fix under 24 hours, this is why i'm still using Apple products :)
Score: 71 Votes (Like | Disagree)
turbineseaplane Avatar
57 months ago
We need an "Even Higher Sierra" release, and only that, this coming year.

High Sierra is just stoned enough that she's letting everyone in...
Maybe if Sierra gets a bit higher, paranoia, and security concerns, might kick in.
Score: 53 Votes (Like | Disagree)
M.PaulCezanne Avatar
57 months ago
But emoji karaoke is working well on iPhone X. Whew!
Score: 52 Votes (Like | Disagree)
rpe33 Avatar
57 months ago
I am Root.
Score: 39 Votes (Like | Disagree)

Popular Stories

Apple Shot on iPhone macro Ashley Lee

Apple Reveals Winning 'Shot on iPhone' Macro Challenge Photos

Wednesday April 13, 2022 6:28 am PDT by
Apple today unveiled the 10 winning photos from the Shot on iPhone Macro Challenge that the company launched earlier this year. "Strawberry in Soda" by Ashley Lee, from San Francisco, U.S.A. Entrants were able to submit unedited macro photos shot on the iPhone 13 Pro and iPhone 13 Pro Max straight from the camera, but photos edited through Apple's Photos app or third-party software were...
facebook meta

Meta Plans to Take a Nearly 50% Commission on Purchases Made Inside the 'Metaverse' Despite Complaining About Apple's 30% App Store Cut

Wednesday April 13, 2022 5:03 am PDT by
Meta, better known as Facebook, plans to take a nearly 50% commission on digital asset purchases made inside the "metaverse," the company has revealed, months after it had complained about the maximum 30% cut that Apple takes for purchases through the App Store. This week, Meta announced new ways it's allowing creators to monetize and earn money from the "metaverse." One way it's enabling...
tim cook mark zuckerberg

Apple Says Plan for Nearly 50% Commission on Metaverse Purchases 'Lays Bare Meta's Hypocrisy'

Thursday April 14, 2022 5:21 am PDT by
Apple has responded to Meta's plan to take a nearly 50% commission for digital asset purchases made inside the metaverse after complaining about fees in the App Store, calling the decision hypocritical. Yesterday, it was revealed that Meta, more commonly known as Facebook, plans to take a steep 47.5% commission for digital asset purchases made inside the so-called "metaverse." The 47.5%...
apple watch series 6 product red back

New Apple Watch Health Features Coming This Year, but Blood Pressure and Blood Sugar Sensors Delayed

Tuesday April 12, 2022 5:45 am PDT by
Apple is still planning to add body temperature monitoring and new health features to the Apple Watch this year, despite experiencing development problems with blood pressure and blood glucose monitoring, in addition to multiple new features in the iPhone's Health app, according to Bloomberg's Mark Gurman. Apple has reportedly been working on an updated sensor for the Apple Watch that is...
13 inch macbook pro m2 mock feature 2

Apple Testing at Least Nine New Macs With Four Different M2 Chip Variants

Thursday April 14, 2022 4:15 pm PDT by
Apple is internally testing several variants of the next-generation M2 chip and the updated Macs that will be equipped with them, reports Bloomberg, citing developer logs. There are "at least" nine new Macs in development that use four different M2 chips that are successors to the current M1 chips. Apple is working on devices with standard M2 chips, the M2 Pro, the M2 Max, and a successor to ...
adobe after effects m1 chart

Adobe After Effects Updated With Native Apple Silicon Support, Up to 3x Faster Speeds Than High-End iMac Pro

Wednesday April 13, 2022 3:48 am PDT by
Adobe has updated its professional video editing software After Effects with native M1 support, offering customers up to 3x faster render speeds on Apple's latest Macs compared to high-end Macs with Intel processors. On M1 computers, Adobe promises up to 2x faster performance in rendering and general app responsiveness. On M1 Ultra, Apple's most high-end chip found in the Mac Studio, Adobe...
ipad pro display apple pencil

Apple's Next Major Display Upgrade Coming to Three Devices

Wednesday April 13, 2022 2:49 am PDT by
Apple's next major display upgrade is set to come to three devices initially, according to multiple recent reports. Apple introduced its first true mini-LED display with the 12.9-inch iPad Pro in 2021, having previously experimented with very similar technology in the Pro Display XDR that launched in 2019. In late 2021, Apple launched two more mini-LED devices, the 14- and 16-inch MacBook...
AirPods Combo Discount Feature Duo

Deals: Save Up to $99 on AirPods Max, AirPods 2, AirPods 3, and AirPods Pro

Thursday April 14, 2022 5:20 am PDT by
Apple's entire current AirPods lineup is seeing notable low prices on Amazon, with up to $99 off the AirPods Max, AirPods 2, AirPods 3, and AirPods Pro. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small payment, which helps us keep the site running. AirPods 2 Amazon has the AirPods 2 at $99.00, down from $129.00. This...