---
title: Major Vulnerability Reported in High Sierra
description: Yesterday morning, a researcher named Lemi Ergin disclosed a major bug in macOS High Sierra. On Twitter, he reported that when making changes to Users and Groups preferences, a login prompt appears. By typing in “root” with no password and clicking “Unlock” multiple times, the system automatically authenticates you. What We Know about the High […]
---

[Skip to content](https://blog.scsprotect.com/major-vulnerability-reported-in-high-sierra#main-content)

[![SCS Logo](https://blog.scsprotect.com/hs-fs/hubfs/logo-1-300x92.png?width=300&height=92&name=logo-1-300x92.png "SCS Logo")](https://scsprotect.com/)

[708-593-3516](tel:708-593-3516)

Search

- There are no suggestions because the search field is empty.

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
  
  Show submenu for Services 
  
    - [Overview](https://scsprotect.com/services/)
    - [Cybersecurity Engagements](https://scsprotect.com/services/cybersecurity-engagements/)
    - [Governance & Compliance](https://scsprotect.com/services/governance-and-compliance/)
    - [Managed Security](https://scsprotect.com/services/managed-security/)
    - [IT Support](https://scsprotect.com/services/it-support/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
  
  Show submenu for Services 
  
    - [Overview](https://scsprotect.com/services/)
    - [Cybersecurity Engagements](https://scsprotect.com/services/cybersecurity-engagements/)
    - [Governance & Compliance](https://scsprotect.com/services/governance-and-compliance/)
    - [Managed Security](https://scsprotect.com/services/managed-security/)
    - [IT Support](https://scsprotect.com/services/it-support/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

## Major Vulnerability Reported in High Sierra

[by Corey Sodes](https://blog.scsprotect.com/author/corey-sodes)  November 29, 2017

Yesterday morning, a researcher named Lemi Ergin disclosed a major bug in macOS High Sierra. On Twitter, he reported that when making changes to Users and Groups preferences, a login prompt appears. By typing in “root” with no password and clicking “Unlock” multiple times, the system automatically authenticates you.

###### **What We Know about the High Sierra Bug**

You can trigger this bug with the following stops, according to [MacRumors](https://www.macrumors.com/2017/11/28/macos-high-sierra-bug-admin-access/):

> 1. Open System Preferences  
>  2. Choose Users & Groups  
>  3. Click the lock to make changes  
>  4. Type “root” in the username field  
>  5. Move the mouse to the Password field and click there, but leave it blank  
>  6. Click unlock, and it should allow you full access to add a new administrator account.

[![](https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png)](https://static.hsstatic.net/BlogImporterAssetsUI/ex/missing-image.png)

This works with any kind of account, including guest accounts. Reportedly, you can even trigger this bug on a locked Mac by using the same credentials.

The current release of High Sierra, 10.13.1, and the current beta are affected. This attack does not work if the user has already password-protected the root account.

###### **Apple’s Official Response**

> Security is a top priority for every Apple product, and regrettably we stumbled with this release of macOS.
> 
> When our security engineers became aware of the issue Tuesday afternoon, we immediately began working on an update that closes the security hole. This morning, as of 8 a.m., the update is available for download, and starting later today it will be automatically installed on all systems running the latest version (10.13.1) of macOS High Sierra.
> 
> We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

Update: Apple officially[released a security patch](https://support.apple.com/en-us/HT208315) earlier today.

###### **More Reading**

- [Ergin’s Twitter](https://twitter.com/lemiorhan/status/935578694541770752)
- [MacRumors Article](https://www.macrumors.com/2017/11/28/macos-high-sierra-bug-admin-access/)
- [Temporary Fix](https://www.macrumors.com/how-to/temporarily-fix-macos-high-sierra-root-bug/) and[Official Update](https://support.apple.com/en-us/HT208315)

***About Secure Compliance Solutions LLC***

*Secure Compliance Solutions LLC (SCS) provides a wide range of cybersecurity consulting and managed security services to small and medium sized businesses (SMB) and government agencies, fortifying their Information Security and Data Privacy programs.  SCS works with its clients to tailor and implement industry-proven frameworks and standards to meet compliance goals and drive consistent security operations.    We raise awareness of current security trends and risks to prepare personnel to recognize and defend against potential security issues.  We implement technical solutions and controls to minimize data risks and liabilities.  Our Managed Security Service provides “constant watch” against both internal and external cyber threats and attacks.  At SCS, we promote a strategy of readiness and resilience that facilitates business risk mitigation and enables dynamic response capabilities to keep your business up and running.*

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Recent Posts

### Categories

[Cyber Attacks](https://blog.scsprotect.com/tag/cyber-attacks)

### Posts by Month

- [October 2025 (1)](https://blog.scsprotect.com/archive/2025/10)
- [June 2025 (2)](https://blog.scsprotect.com/archive/2025/06)
- [April 2025 (2)](https://blog.scsprotect.com/archive/2025/04)
- [March 2025 (1)](https://blog.scsprotect.com/archive/2025/03)
- [February 2025 (1)](https://blog.scsprotect.com/archive/2025/02)
- [January 2025 (1)](https://blog.scsprotect.com/archive/2025/01)
- [November 2024 (1)](https://blog.scsprotect.com/archive/2024/11)
- [October 2024 (1)](https://blog.scsprotect.com/archive/2024/10)
- [August 2024 (1)](https://blog.scsprotect.com/archive/2024/08)
- [June 2024 (1)](https://blog.scsprotect.com/archive/2024/06)
- [April 2024 (2)](https://blog.scsprotect.com/archive/2024/04)
- [February 2024 (1)](https://blog.scsprotect.com/archive/2024/02)
- [October 2023 (1)](https://blog.scsprotect.com/archive/2023/10)
- [February 2023 (1)](https://blog.scsprotect.com/archive/2023/02)
- [November 2021 (2)](https://blog.scsprotect.com/archive/2021/11)
- [October 2021 (1)](https://blog.scsprotect.com/archive/2021/10)
- [December 2020 (2)](https://blog.scsprotect.com/archive/2020/12)
- [November 2020 (2)](https://blog.scsprotect.com/archive/2020/11)
- [October 2020 (4)](https://blog.scsprotect.com/archive/2020/10)
- [September 2020 (1)](https://blog.scsprotect.com/archive/2020/09)
- [August 2020 (1)](https://blog.scsprotect.com/archive/2020/08)
- [July 2020 (1)](https://blog.scsprotect.com/archive/2020/07)
- [June 2020 (1)](https://blog.scsprotect.com/archive/2020/06)
- [May 2020 (1)](https://blog.scsprotect.com/archive/2020/05)
- [April 2018 (1)](https://blog.scsprotect.com/archive/2018/04)
- [March 2018 (5)](https://blog.scsprotect.com/archive/2018/03)
- [February 2018 (3)](https://blog.scsprotect.com/archive/2018/02)
- [January 2018 (5)](https://blog.scsprotect.com/archive/2018/01)
- [December 2017 (3)](https://blog.scsprotect.com/archive/2017/12)
- [November 2017 (3)](https://blog.scsprotect.com/archive/2017/11)
- [October 2017 (6)](https://blog.scsprotect.com/archive/2017/10)
- [May 2017 (1)](https://blog.scsprotect.com/archive/2017/05)
- [January 2016 (3)](https://blog.scsprotect.com/archive/2016/01)
- [November 2015 (1)](https://blog.scsprotect.com/archive/2015/11)
- [October 2015 (1)](https://blog.scsprotect.com/archive/2015/10)

see all

## Read On

### [Vulnerability Scanning Vs. Penetration Testing](https://blog.scsprotect.com/vulnerability-scanning-vs-penetration-testing)

## **What Is Vulnerability Scanning?**

Vulnerability Scanning is an automated process of identifying...

### [SCS’ 2016 Cybersecurity Outlook](https://blog.scsprotect.com/scs-2016-cybersecurity-outlook)

## **SCS’s 2016 Cybersecurity Outlook**

In 2015, we witnessed a number of high profile cyberattacks and...

### [The Weekly Roundup (2020-November-14)](https://blog.scsprotect.com/the-weekly-roundup-2020-november-14)

## **2020 – November 09**

### Breaches Reported

The group Luxottica (who owns LensCrafters, Target...

[![SCS Logo](https://blog.scsprotect.com/hs-fs/hubfs/logo-1-300x92.png?width=300&height=92&name=logo-1-300x92.png "SCS Logo")](https://scsprotect.com/)

### © Copyright 2024 SCS

[TERMS & CONDITIONS](https://scsprotect.com/termsandconditions/) [PRIVACY POLICY](https://scsprotect.com/privacypolicy/)

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

[708-593-3516](tel:708-593-3516)

[Follow us on Twitter](https://twitter.com/SecCompSol) [Follow us on Facebook](https://www.facebook.com/SecureComplianceSolutions) [Follow us on Facebook](https://github.com/Secure-Compliance-Solutions-LLC) [Follow us on LinkedIn](https://www.linkedin.com/authwall?trk=bf&trkInfo=AQGwIqLZLJ6-iwAAAYtsHqqYSjD2Uqv1U_cM0b0djtojM7EUQm9GGXH7fhtuHHmmlyWJJmhQ37JCuRdAjRdXPVOl9FdDVKqOwdqHFc24h_-3zZX1baMyqNlXtLKIKEaU_HG3aa4=&original_referer=&sessionRedirect=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsecure-compliance-solutions-llc%2Fabout%2F)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Corey Sodes",
    "url" : "https://blog.scsprotect.com/author/corey-sodes"
  },
  "dateModified" : "2023-10-30T18:13:40.997Z",
  "datePublished" : "2017-11-29T19:13:00.000Z",
  "headline" : "Major Vulnerability Reported in High Sierra",
  "mainEntityOfPage" : {
    "@id" : "https://blog.scsprotect.com/major-vulnerability-reported-in-high-sierra",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scsprotect.com/hubfs/logo-1-300x92.png"
    },
    "name" : "Secure Compliance Solutions"
  }
}
```