Apple releases macOS High Sierra security fix for critical root vulnerability, says it's auditing its development processes to prevent future flaws
and thoroughly — does Apple fix macOS security holes? Chris Burns / SlashGear : MacOS flaw fix update out now Lory Gil / iMore : Having problems with file sharing after installing the macOS High Sierra ‘root’ … Michael Allison / MSPoweruser : Apple apologises for security flaw in MacOS High Sierra, issues bug fixing update Shaun Nichols / The Register : As Apple fixes macOS root password hole, here's what went wrong John Voorhees / MacStories : Apple Fixes Root Access Bug with Security Update Jonny Evans / Computerworld : Apple apologizes, issues Mac login security patch
Context & Ripple Effects
The root hole — a password prompt that authenticates with an empty password — had been sitting in plain sight: it was posted to Apple's support forum on November 13, roughly two weeks before it went viral and forced a fix. The patch landed alongside an unusual public apology and a promise that Apple is auditing its development processes.
It is also not an isolated lapse for this release: in October Apple shipped fixes for an APFS Disk Utility flaw that displayed passwords instead of hints and a Keychain bug that let apps dump passwords, so the root hole lands on top of an already rough security cycle for High Sierra.
First-order effects
- Every Mac user on High Sierra needs to apply the emergency update immediately, since any local user — or anyone at an unlocked login screen — could gain full root access with no password.
- Users who installed the fix are reporting file-sharing problems afterward, meaning some are choosing between the vulnerability and a broken feature while waiting on Apple.
Second-order effects
- Apple's own upgrade path undermines its fix: machines upgraded from 10.13.0 to 10.13.1 lose the patch and have to re-install it manually and reboot, as covered in the broken-patch reports — turning a one-time fix into an ongoing support burden.
- Enterprise Mac administrators now have to verify patch state across their fleets rather than trust version numbers, since a machine can show 10.13.1 yet remain exposed.
Third-order effects
- If the pattern holds — multiple credential-handling flaws in one release cycle plus a patch that upgrades silently undo — scrutiny shifts from individual bugs to Apple's testing and regression-checking of security updates themselves, which is exactly what the announced process audit concedes.
- A visible apology from a company that rarely issues them raises the bar for how quickly major platform vendors must respond once a flaw circulates publicly, compressing the window between disclosure and mandatory patching.
The trend: Platform vendors are being judged less on whether critical flaws occur than on the speed and reliability of their patch pipeline — and Apple's own upgrade process just failed that test.