Search

macOS High Sierra Bug Can Give Anyone Root Access to Your Mac - How to Fix

Advertisement
macOS High Sierra Bug Can Give Anyone Root Access to Your Mac - How to Fix

Apple Inc. customers have discovered a significant security flaw in the latest version of the operating system for Mac computers that allows anyone to log in without a password, potentially making private user data vulnerable.

The issue, discovered in the MacOS High Sierra operating system for laptops and desktops that was released in September, allows people to enter the word “root” when prompted for a username, and provide no password when logging on to the device. The glitch allows anyone to access the file system for a Mac, exposing private documents on that particular computer. One user reported the ability to also access the computer using the root login remotely.

The glitch is a rare and potentially embarrassing failure for Apple, whose software is generally known for being less prone to hacking and malware infections than Windows software from Microsoft Corp. The previous version of the operating system didn’t appear to be affected by the bug.

“A password prompt that authenticates as root with an empty password would be a black eye for any OS. Never mind one from a security and privacy-conscious company such as Apple,” Steve Troughton-Smith, a Mac software developer, wrote on Twitter.

Apple spokesman Bill Evans said the company is “working on a software update to address this issue. In the meantime, setting a root password prevents unauthorized access to your Mac.”

Tests of the flaw indicate that it could be used to alter a user’s system settings that normally require a chosen username and password. Some settings include changing key security preferences -- like enabling or disabling a computer’s firewall or storage drive encryption.

The flaw was publicized Tuesday on Twitter by Lemi Orhan Ergin, a software engineer based in Turkey. Edward Snowden, a key voice in the information security community after being the center of many years of National Security Agency leaks, commented on the disclosure. “Imagine a locked door, but if you just keep trying the handle, it says ‘oh well’ and lets you in without a key,” he wrote on Twitter.

Until Apple releases a new version of the software or patches the flaw, users can fix the issue by assigning their own password to the root account. This can be done by navigating to System Preferences, selecting Users and Groups, clicking Login Options on the left side of the menu, clicking the Join button next to Network Account Server, clicking Open Directory Utility, then clicking Edit in the Mac’s menu bar to assign a password. Apple also has instructions available on its website.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Apple, macOS, macOS High Sierra
 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco F7 Launch Date, Price in India, Design and Key Features Leaked Online
  2. Vivo Y400 Pro 5G India Launch Date Confirmed; Design Revealed
  3. OnePlus Nord 5 Series, OnePlus Buds 4 to Launch in India on This Date
  4. Vivo X200 FE Global Launch Confirmed; Design Teased
  5. Oppo K13x 5G India Launch Date, Price Range and Key Features Revealed
  6. Hisense U7Q Mini-LED TV Launched in India With These Features
  7. Oppo Reno 14 5G Series, Watch X2 Mini, Enco Buds 3, Pad SE to Launch Globally
  8. This Is When Axiom-4 Mission Carrying Shubhashu Shukla Will Be Launched
  9. Realme Narzo 80 Lite 5G Launched in India With 6,000mAh Battery: See Price
  10. Oppo K13 Turbo Pro Key Specifications Leaked Online
  1. The Witcher 4 Will Target 60 FPS on Consoles, but Series S Will Be 'Extremely Challenging' Says CD Projekt Red
  2. Oppo Reno 14 5G Series Global Launch Teased Alongside Watch X2 Mini, Enco Buds 3 and Pad SE
  3. Microsoft Begins Testing AI Agents in Windows 11, Brings Option to Share Recall Snapshots in Europe
  4. watchOS 26 to Bring Control Center Customisation Options with User-Defined Toggles
  5. Tecno Pova 7 5G Series India Launch Teased; Confirmed to Be Available on Flipkart
  6. Oppo K13 Turbo Pro Key Specifications Leaked; Could Be Equipped With Snapdragon 8s Gen 4 SoC
  7. Lenovo Legion Pro 7i (2025) With Intel Core Ultra 9 HX CPU, Up to Nvidia GeForce RTX 5090 GPU Launched
  8. Hisense U7Q Mini-LED TV With 144Hz Gaming Support, Built-in Subwoofer Launched in India
  9. OnePlus Nord 5, Nord CE 5, and Buds 4 India Launch Date Set for July 8; Key Features, Availability Revealed
  10. OpenAI Makes Canvas in ChatGPT Downloadable, Adds New Capabilities to Projects
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »