X

Apple flaw allows MacOS High Sierra logins without passwords

The latest version of Apple’s software has a glaring hole in it: You can log in with just the username "root."

Alfred Ng Senior Reporter / CNET News
Alfred Ng was a senior reporter for CNET News. He was raised in Brooklyn and previously worked on the New York Daily News's social media and breaking news teams.
Alfred Ng
2 min read
screen-shot-2017-11-28-at-3-33-43-pm

CNET independently confirmed that you can log in on MacOS High Sierra with just the username "root."

CNET

The username is the "root" of all problems for Apple's latest operating system.

Watch this: Apple's huge password bug in Macs can be fixed

It turns out you don't need a password to log in to a locked Apple device using MacOS High Sierra -- just the username "root."

By heading to your device's System Preferences, under Users & Groups, you can click on the lock and get hit with a prompt asking for a username and password to change settings. Then, instead of entering a password, you can type in "root" for the username and leave the password field empty.

After clicking unlock several times, it should eventually open up, no passwords necessary. Lemi Orhan Ergin, the founder of Software Craftsmanship Turkey, discovered the security flaw and tweeted it out to Apple Support on Tuesday.

CNET independently confirmed this security flaw exists. 

"We are working on a software update to address this issue," an Apple spokesperson said. "In the meantime, setting a root password prevents unauthorized access to your Mac. To enable the Root User and set a password, please follow the instructions here. If a Root User is already enabled, to ensure a blank password is not set, please follow the instructions from the 'Change the root password' section."

The simple exploit means anybody with physical access to your MacOS High Sierra device can log in on your computer, no matter how secure your passwords are.

Amit Serper, a security researcher from Cybereason, demonstrated that the bug works even on the login screen after restarting the computer:

The bug works for every aspect of the OS that would normally require a password, which means someone could also get access to your Keychain, containing all your passwords.

Enlarge Image

A demonstration of the security flaw.

CNET

MacOS High Sierra was also plagued with a password issue when it launched, after a former NSA hacker showed that he could extract sensitive data from Keychain using an app downloaded online.

There's a workaround for the "root" flaw until Apple fixes it. You can turn guest users off, or change the root password from your directory utility, as 9to5Mac suggested.

Kurt Opsahl, the general counsel for the Electronic Frontier Foundation, recommended creating a username "root" and setting a password to solve the blatant issue.

First published Nov. 28, 12:44 p.m PT.
Update, 1:15 p.m. PT: Adds details about how to fix the issue as well as what other things the "root" bug can access. Update, 3:25 p.m. PT: Adds a statement from Apple. 

Does the Mac still matter? Apple execs explain why the MacBook Pro was over four years in the making, and why we should care.

Tech CultureFrom film and television to social media and games, here's your place for the lighter side of tech.