macOS High Sierra's App Store System Preferences Can Be Unlocked With Any Password [Updated]

A bug report submitted on Open Radar this week has revealed a security flaw in the current version of macOS High Sierra that allows the App Store menu in System Preferences to be unlocked with any password.

mac app store preferences
MacRumors is able to reproduce the issue on macOS High Sierra version 10.13.2, the latest public release of the operating system, on an administrator-level account by following these steps:

• Click on System Preferences.
• Click on App Store.
• Click on the padlock icon to lock it if necessary.
• Click on the padlock icon again.
• Enter your username and any password.
• Click Unlock.

As mentioned in the radar, we can confirm that the App Store preferences login prompt does not accept an incorrect password with a non-administrator account, meaning there is no behaviour change for standard user accounts.

We also weren't able to bypass any other System Preferences login prompts with an incorrect password, with any type of account, so more sensitive settings such as Users & Groups and Security & Privacy are not exposed by this bug.

Apple has fixed the bug in the latest beta of macOS 10.13.3, which currently remains in testing and will likely be released at some point this month. The bug doesn't exist in macOS Sierra version 10.12.6 or earlier.

On the current macOS 10.13.2, the bug gives anyone with physical, administrator-level access to a Mac the ability to disable settings related to automatically installing macOS software, security, and app updates.

This is the second password-related bug to affect macOS High Sierra in as many months, following a major security vulnerability that enabled access to the root superuser account with a blank password on macOS High Sierra version 10.13.1 that Apple fixed with a supplemental security update.

Following the root password vulnerability, Apple apologized in a statement and added that it was "auditing its development processes to help prevent this from happening again," so this is a rather embarrassing mishap.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

It's worth noting that the App Store preferences are unlocked by default on administrator accounts, and given the settings in this menu aren't overly sensitive, this bug is not nearly as serious as the earlier root vulnerability.

Apple will likely want to fix this bug sooner rather than later, so it's possible we'll see a similar supplemental update released at some point, or perhaps it will fast track the release of macOS High Sierra version 10.13.3. Apple did not immediately respond to our request for comment on this matter.

In the meantime, if you keep your App Store preferences behind lock, you'll want to be more diligent in ensuring that you log out of your administrator account when you are away from your Mac. Alternatively, until macOS 10.13.3 is released, users can use a standard account rather than an administrator one.

While this bug isn't as dangerous as the root password vulnerability, being able to bypass a login prompt with any password is something that obviously shouldn't be possible and is an embarrassing oversight for Apple.

Related Forum: macOS High Sierra

Popular Stories

AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 3, AirPods Pro 2 and AirPods 4

Tuesday October 7, 2025 11:27 am PDT by
Apple today released new firmware designed for the AirPods Pro 3, prior-generation AirPods Pro 2, and the AirPods 4 models. The firmware has a build number of 8A358, up from 8A356. There's no word on what's include in the updated firmware, but the prior 8A356 update added iOS 26 features to the AirPods Pro 2, AirPods Pro 3, and AirPods 4 with ANC. The software introduced better audio quality ...
tag heuer made for iphone

New TAG Heuer Smartwatches Now 'Made for iPhone'

Wednesday October 8, 2025 8:41 am PDT by
TAG Heuer today announced the Connected Calibre E5 smartwatch, now featuring "Made for iPhone" certification as the watchmaker abandons Google's Wear OS. Three years after launching the Calibre E4, the Connected Calibre E5 comes in two case sizes: 45mm and a new, more compact 40mm. They are powered by the Qualcomm Snapdragon 5100+. The 45mm model features a 1.39-inch AMOLED display, while ...
iphone 17 magsafe silicon rings 1

Apple Modifies In-Store MagSafe Stands to Prevent iPhone 17 Marks

Wednesday October 8, 2025 4:41 am PDT by
Apple has quietly added a protective silicone ring to its in-store MagSafe charging stands following reports of marks appearing on some iPhone 17 series display models, according to Consomac. The apparent move comes after Apple last month confirmed that worn MagSafe chargers in retail stores were causing what appeared to be scratches on the iPhone 17 Pro and iPhone 17 Pro Max. There have...
apple invite colorado%402x

Apple Hosts Unusual Colorado Event to Showcase Latest Hardware

Thursday October 9, 2025 1:17 pm PDT by
Apple has invited a group of social media influencers to Colorado this week for an unusual event involving group hiking, trail running, and other outdoor activities designed to showcase the company's recently launched iPhone 17 Pro Max, AirPods Pro 3, and Apple Watch Ultra 3. An invitation was shared on X (Twitter) by photographer Johnny Hawk, featuring a simple message: "Hi Johnny. We're so ...
spring 2022 possible macs

When Will Apple's Macs Get M5 Chips? 2025-2026 Launch Timeline

Wednesday October 8, 2025 3:59 pm PDT by
We're just about due for the next-generation Apple silicon chip, which will kick off a new wave of Mac refreshes. The M5 chip is expected to make an appearance in some new products before the end of the year, but most Mac refreshes will happen in 2026. We've rounded up current rumors on when we might see updates for Apple's notebook and desktop machines. MacBook Pro The MacBook Pro could ...
10

Apple to Launch New Products Starting Next Week, Claims Dubious Leak [Updated]

Friday October 10, 2025 5:57 am PDT by
Update: the Naver account appears to be referencing a speculative post on X by Vadim Yuryev, dated October 6. The original article follows. Apple will announce new products through a series of press releases beginning as soon as next week, according to a dubious claim posted on the Korean blog Naver. The Naver blog account yeux1122, which aggregates rather than originates Apple...
10

Apple Event This October? Here's the Latest on What to Expect

Thursday October 9, 2025 7:00 am PDT by
While it is unclear if Apple will host an October event this year, or stick to press releases, rumors suggest it will announce several new products this month. The graphic for Apple's "Unleashed" event in October 2021 Below, we have recapped everything to know about a potential Apple event this October. When The table below outlines when Apple teased its October launches over the past...
ipad mini 7 feature blue

iPad Mini 8 on the Way: Expected Features and Release Timeline

Monday October 6, 2025 5:05 am PDT by
A new iPad mini is "absolutely" on the way, according to Bloomberg's Mark Gurman. So what should we expect from the successor to the iPad mini 7 that Apple released a year ago? Processor and Performance Apple is working on a next-generation version of the iPad mini (codename J510/J511) that features the A19 Pro chip, according to information found in code that Apple mistakenly shared in...
iOS 26

Everything New in iOS 26.1 Beta 2

Monday October 6, 2025 3:54 pm PDT by
Apple released the second beta of iOS 26.1 and iPadOS 26.1, introducing useful changes to alarms, multitasking on the iPad, and more. There are also subtle tweaks to some of the Liquid Glass design elements as Apple continues to refine iOS 26. Alarms and Timers Alarms set using the Clock app now have a slide to stop button rather than a tap to stop button on the Lock Screen. To snooze an...

Top Rated Comments

Crosscreek Avatar
101 months ago
Oh Apple....Lol

It just works....for anybody.
Score: 99 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
101 months ago
THIS WILL BE THE END OF THE WORLD!

WHAT HAS HAPPENED TO APPLE LATELY!? IF SOMEONE HAD ACCESS TO MY MACHINE THEY COULD CHANGE A COUPLE FAIRLY MEANINGLESS APP STORE PREFERENCES!!!!
Score: 42 Votes (Like | Disagree)
shareef777 Avatar
101 months ago
Passwords: now optional!
Score: 42 Votes (Like | Disagree)
Darryl.Jenks Avatar
101 months ago
Wow. Just wow.
Score: 37 Votes (Like | Disagree)
techno-Zen Avatar
101 months ago
Unreal, maybe focus less on retail store trees and more on stuff like this
Score: 33 Votes (Like | Disagree)
Chupa Chupa Avatar
101 months ago
A tad bit disturbing because it's so blatant and Apple has stated security is a feature of its products. These type of basic omissions belie its claims. Feels like Mac OS is becoming Windows with all these security patch updates. Maybe Apple needs to slow down here a bit and get back to basics.
Score: 30 Votes (Like | Disagree)