macOS upgrades from High Sierra 10.13.0 to 10.13.1 break “root” bug patch issued earlier this week; fix by re-installing patch after upgrade, rebooting computer
WHEN A COMPANY like Apple rushes out a software patch for a critical security bug, it deserves praise for protecting its customers quickly.
Context & Ripple Effects
Apple shipped an emergency fix on November 29 for a flaw that let anyone authenticate as root with an empty password at the login prompt, days after the bug surfaced publicly — though it had been sitting in an Apple support forum post since November 13. The company followed up by saying it was auditing its development processes.
That fix is already fraying: upgrading from High Sierra 10.13.0 to 10.13.1 silently removes the root patch, so the version bump meant to move users forward actually regresses them on security. It is the second time in two months a High Sierra update has had to chase a credential-handling flaw, following October's fix for the APFS Disk Utility bug that displayed passwords instead of hints.
First-order effects
- Mac users who take the 10.13.1 upgrade are unprotected against the root bypass again until they manually re-install the November 29 patch and reboot — the update path itself is the exposure.
Second-order effects
- Enterprise and IT administrators can no longer treat 'fully updated' as 'patched' on High Sierra, forcing them to verify the root fix separately on every machine rather than trusting the OS version number.
Third-order effects
- With the empty-password bug, the forum-post delay, and this regression stacking within weeks, Apple's stated development-process audit points toward slower, more tested release cadences for security fixes — trading speed of response for reliability of the fix itself.
The trend: Emergency security patching is outrunning regression testing at Apple, turning each rushed fix into a new failure point across the installed base.