Apple releases macOS High Sierra security fix for critical root vulnerability
If you're running macOS High Sierra, it's time to update your Mac as soon as possible. Apple has released a security update that addresses the security vulnerability discovered yesterday afternoon.
Context & Ripple Effects
Apple shipped an emergency update for a High Sierra flaw that let anyone authenticate as root from the login prompt with an empty password — the bug surfaced publicly on November 28 via Bloomberg after circulating among Mac users. The most damaging detail is timing: the trick had been posted to Apple's own support forum on November 13, meaning it sat unaddressed for roughly two weeks before going viral.
It is also not an isolated slip this release cycle — back in October Apple patched a High Sierra Disk Utility flaw that displayed passwords instead of hints, alongside a Keychain bug that let apps dump stored passwords. The root hole is worse in kind because it needs no credentials at all.
First-order effects
- Every Mac running macOS High Sierra is exposed until patched, so the immediate action falls on users to install the update Apple pushed out within a day of public disclosure.
- Apple is now auditing its development processes, an admission that the flaw passed through its QA pipeline undetected despite sitting in plain sight on its support forum.
Second-order effects
- The patch itself proved fragile: upgrading from 10.13.0 to 10.13.1 reintroduced the root vulnerability, forcing users to re-install the fix and reboot — a second wave of exposure created by Apple's own update sequencing.
- Enterprise IT teams managing Mac fleets inherit the re-install burden, since any machine that takes the OS upgrade silently regresses to an unauthenticated-root state.
Third-order effects
- A pattern of credential-handling flaws across one release cycle points toward tighter scrutiny of Apple's security process — disclosure timelines, forum monitoring, and regression testing of patches against concurrent updates — as the real product under review.
- If patch-fragility becomes routine, the trust model that lets consumers defer to vendor update cadence weakens, pushing toward independent verification of fixes rather than assumed completeness.
The trend: Consumer OS security is shifting from discrete bug fixes to process accountability, where how a vendor finds, discloses, and keeps patches intact matters as much as the flaw itself.