Apple Releases macOS High Sierra Security Update to Fix Root Password Vulnerability

Apple today released Security Update 2017-001 to fix a serious vulnerability that enables access to the root superuser account with a blank password on any Mac running macOS High Sierra version 10.13.1.

rootbug
The critical bug, which gained attention after it was tweeted by developer Lemi Ergin yesterday, lets anyone gain administrator privileges by simply entering the username "root" and a blank password in System Preferences > Users & Groups.

The security update is rolling out on the Mac App Store now, and it should be installed by all users running macOS High Sierra as soon as possible. Regardless, starting later today, Apple said the security update will be automatically installed on all Macs running macOS High Sierra 10.13.1.

Apple has since apologized for the vulnerability in a statement issued to MacRumors:

Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.

When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

The vulnerability does not affect macOS Sierra or any other previous version of the operating system.

Top Rated Comments

aforty Avatar
48 months ago
How embarrassing...

I wish Apple did a better job testing their releases. We used to enjoy such high quality when it came to software updates and releases.
Score: 42 Votes (Like | Disagree)
bwintx Avatar
48 months ago
That was quick
And it was utterly necessary that it be just that.
Score: 36 Votes (Like | Disagree)
dannyyankou Avatar
48 months ago
That was quick
Score: 34 Votes (Like | Disagree)
AbSoluTc Avatar
48 months ago
How embarrassing...

I wish Apple did a better job testing their releases. We used to enjoy such high quality when it came to software updates and releases.
You ever heard of Windows? Perhaps you should read up on that OS if you haven't.

Also, give me a break. Nobody finds everything, not even "Apple". Patched quickly and painlessly. Move along.
Score: 31 Votes (Like | Disagree)
longofest Avatar
48 months ago
You ever heard of Windows? Perhaps you should read up on that OS if you haven't.

Also, give me a break. Nobody finds everything, not even "Apple". Patched quickly and painlessly. Move along.
Three... count 'em... THREE... critical and ridiculous security issues with Mac OS High Sierra within as many months. This one, the Disk utility one, and the keychain one. And that's just the security issues...

There's no excuse for it. Saying "well, microsoft is just as bad" just means that Apple is stooping to Microsoft's level... but I'd actually venture to say that Apple is starting to get worse than Microsoft when it comes to Mac OS vs Windows.
Score: 13 Votes (Like | Disagree)
discuit Avatar
48 months ago
This is actually an argument in favor of public disclosure of vulnerabilities. Lemi Orhan Ergin was catching a lot of criticism yesterday for posting it on twitter, but if this bug had been reported privately, it would have taken much longer to fix, while malicious actors would be able to exploit it all along.
Score: 10 Votes (Like | Disagree)

Top Stories

16 inch macbook pro m2 render

Gurman: Redesigned MacBook Pros to Launch Between September and November

Sunday July 18, 2021 7:39 am PDT by
Apple can be expected to release its redesigned 14-inch and 16-inch MacBook Pros sometime between September and November, as part of another packed fall season for new product launches, according to Bloomberg journalist Mark Gurman. In the latest edition of his Power On newsletter, Gurman says that the new MacBook Pros will go into production in the third quarter and can be expected to be...
General Apps Messages

All Three Major U.S. Carriers and Google Adopt Rich Communication Services, But No Sign of Apple Interest

Tuesday July 20, 2021 1:15 pm PDT by
For the last several years, Google has been pushing a new communications protocol called Rich Communication Services, or RCS. RCS is designed to replace SMS, the current text message standard, and it offers support for higher resolution photos and videos, audio messages, bigger file sizes, better encryption, improved group chat, and more. Verizon today announced that it is planning to adopt...
iPhone SE Cosmopolitan Clean

'iPhone SE 3' With A14 Bionic Chip and 5G Expected in First Half of 2022

Monday July 19, 2021 1:31 am PDT by
Apple plans to update the iPhone SE, its 4.7-inch entry-level iPhone, with an updated A14 Bionic processor from the iPhone 12 series in the first half of next year, according to a report from DigiTimes. DigiTimes' report follows in the footsteps of reliable Apple analyst Ming-Chi Kuo, who reported last month the iPhone SE would receive an updated processor and 5G capabilities in the first...
apple tv 4k design green

Apple Releases tvOS 14.7 for Apple TV HD and Apple TV 4K

Monday July 19, 2021 10:04 am PDT by
Apple today released tvOS 14.7, the seventh update to the tvOS 14 operating system that initially debuted in September 2020. tvOS 14.7 comes two months after the launch of the tvOS 14.6 update. tvOS 14.7, which is a free update, can be downloaded over the air through the Settings app on the Apple TV by going to System > Software Update. ‌‌Apple TV‌‌ owners who have automatic software ...
nso israeli surveillance firm

Report: Pegasus Spyware Sold to Governments Uses Zero-Click iMessage Exploit to Infect iPhones Running iOS 14.6

Monday July 19, 2021 12:35 am PDT by
Journalists, lawyers, and human rights activists around the world have been targeted by authoritarian governments using phone malware made by Israeli surveillance firm NSO Group, according to multiple media reports. An investigation by 17 media organizations and Amnesty International's Security Lab uncovered a massive data leak, indicating widespread and continuing abuse of the commercial...
iPhone 13 Always On Feature

iPhone 13 May Feature Apple Watch-Inspired Always-On Display

Sunday July 18, 2021 8:26 am PDT by
Following a successful supercycle launch of the iPhone 12 last year, Apple aims to make another "big splash" with its upcoming 2021 iPhones, which can be expected to feature larger batteries, smaller notches, improved performance, and more advanced displays that may sport an always-on mode. In the latest publication of his weekly Power On newsletter, Bloomberg journalist Mark Gurman...
AirPods Pro Beta Firmware

AirPods Pro Beta Firmware Now Available

Wednesday July 21, 2021 6:50 am PDT by
Upcoming AirPods Pro firmware updates are now available to Apple Developer Program members as beta versions. AirPods Pro firmware beta one features FaceTime Spatial Audio and Ambient Noise Reduction. Custom Transparency mode, including Conversation Boost, was initially expected to be included in the beta but appears to have been delayed for a later version. Apple made the announcement...
magsafe battery pack 2

Photos of Apple's New MagSafe Battery Pack Provide First Look at Thickness

Monday July 19, 2021 6:36 am PDT by
Apple's new MagSafe Battery Pack will begin arriving to customers around the world this week, and one lucky person has already snagged one. Steven Russell from Memphis, Tennessee said he managed to pick up the MagSafe Battery Pack from a local Apple Store over the weekend, and he has since shared photos on Reddit, providing a closer look at its design and thickness. Russell shared some...
apple releases ios 14 7

Apple Releases iOS 14.7 With MagSafe Battery Support and Apple Card Family Credit Limit Combining

Monday July 19, 2021 10:06 am PDT by
Apple today released iOS 14.7, marking the seventh major update to the iOS operating system that came out in September 2020. iOS 14.7 comes two months after the launch of iOS 14.6, a major update that added Apple Card Family Support, Podcast Subscriptions, and more. The iOS 14.7 update can be downloaded for free and the software is available on all eligible devices over-the-air in the...
magsafe battery pack solo

Hands-On With Apple's MagSafe Battery Pack

Tuesday July 20, 2021 11:14 am PDT by
The new MagSafe Battery Pack that Apple debuted this week is arriving to customers starting today and it's also now available for in-store pickup in many Apple retail locations around the world. We snagged one this morning and thought we'd take a look at it to let MacRumors readers know if it's worth the $99 asking price. Subscribe to the MacRumors YouTube channel for more videos. As the name ...