MacOS High Sierra Vulnerability Allows Anyone Root Access Without a Password

30 Nov 2017

MacOS High Sierra Vulnerability Allows Anyone Root...

Apple users have been warned of a serious vulnerability with the latest version of Apple’s operating system, macOS High Sierra, after it was discovered that anyone can potentially gain full access to a machine without requiring a password.

The widely reported vulnerability is exploitable via the authentication dialog box and allows any rogue user with a foothold on a target computer the ability to gain the deepest level of access, known as “root” privileges. The exploit process is simple and can be done by following these steps from admin or guest account:

  • Open System Preferences on the machine;
  • Select Users & Groups;
  • Click the lock icon to make changes;
  • Enter “root” in the username field of a login window;
  • Move the cursor into the Password field and hit the enter button a few times, leaving it blank.

From there, macOS High Sierra logs the unauthorised user in with root privileges, allowing them access as a “superuser” with permission to read and write to system files, including those in other macOS accounts as well.

Although clearly a very serious issue, anyone seeking to exploit this vulnerability would need physical access to the target machine. Apple have urgently rushed out a patch to address this issue and we strongly encourage Mac users to update their OS at their earliest opportunity. Details of the update are available via the following support page:

If unable to update immediately, users should mitigate the vulnerability by ensuring unattended devices are locked and by carefully monitoring any remote desktop access controls. To manually mitigate the risk, Mac users should also enable the root user with a password to prevent the account from being accessed with a blank password.


By Olly Jones

Senior Cyber Threat Analyst

Share this article


Your free global geopolitical
risk dashboard

PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.

The Risk Portal gives users up-to-date information and analysis on global affairs.

The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.

Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.

Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.

Visit the Risk Portal

Subscribe to our Cyber Bytes Newsletter

Keep yourself in the loop with PGI by signing up to our Monthly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.

Get in touch today

For more information on how we can help you or your business, please contact us via:

Related News

CISMP, CISSP and CISM - what's in an acronym?

20 Mar 2017

There is a wide range of different security courses available, and a mind-boggling array of certific...

Read news article

International Womens Day - Pioneering Women in Tec...

08 Mar 2017

Pioneering Women in Technology – Katherine JohnsonThe Oscar season has been and gone. The...

Read news article

Law Firms and why they need cyber security

06 Mar 2017

Suffering a data breach can be devastating for any company but for law firms the impacts can be part...

Read news article
Back to the News Hub

Follow us

+44 (0)207 887 2699
©2017 PGI - Protection Group International Ltd. All rights reserved.
PGI - Protection Group International Ltd is registered in England & Wales, reg. no. 07967865
Registered address: Cascades 1, 1190 Park Avenue, Aztec W, Almondsbury, Bristol BS32 4FP