macOS High Sierra bug gives access via password prompt that authenticates as root with empty password
Security bug found in latest version of MacOS High Sierra — Company says it is working on a software update to fix issue — Apple Inc. customers have discovered a significant security flaw …
Context & Ripple Effects
The root-authentication flaw is the second serious credential-handling failure in High Sierra within weeks: Apple had already patched an APFS Disk Utility bug that displayed passwords instead of hints alongside a Keychain vulnerability in October. What makes this one worse is exposure time — the bug was posted to Apple's own support forum on November 13, roughly two weeks before it became widely known and a fix shipped.
First-order effects
- Every Mac running an unpatched copy of High Sierra can be logged into as root with an empty password at the prompt, giving full system access to anyone with physical access until Apple's update lands.
Second-order effects
- Apple's response goes beyond the patch itself — the company says it is auditing its development processes, an acknowledgment that the flaw escaped both internal review and its own support forums for days.
- The incident lands on top of the October Keychain and Disk Utility fixes, forcing Apple to defend the security reputation of a release cycle that has now produced repeated credential-exposure bugs.
Third-order effects
- If the pattern holds — flaws surfacing publicly before vendors act — expect faster community disclosure norms and more pressure on Apple to show its security review caught critical authentication bugs before users do.
The trend: Desktop operating systems are being judged less on feature cadence than on whether their security review catches authentication flaws before public disclosure does.