MacOS High Sierra vulnerability was publicly disclosed in an Apple forum weeks ago

Apple only issued a public statement about it on November 28.
 By 
Jack Morse
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

While Apple scrambles to issue a software fix for a major macOS High Sierra vulnerability, astute observers are wondering what took the company so long to react — after all, the problem was known about weeks ago.

It seems that on November 13, a commenter on an Apple developer forum disclosed the very vulnerability that today threw the infosec community into a frenzy. Oh, and it was called out 9 days ago on Twitter as well.

And just how bad is this security threat? Well, it's not good. Essentially, it gives anyone with access to an unlocked computer the ability to set themselves as the root user — as well as log back in later to the locked computer at a time of their choosing.

To execute the hack, you only needed to go to System Preferences > Users & Groups, then enter "root" as your user name while leaving the password field blank. Try this a few times until you have access. It's that simple. The exploit was first explained by Apple developer chethan177.

Again, chethan177 posted this on November 13. Apple only issued instructions on how to protect yourself against this on November 28.

Whether or not anyone tried to responsibly disclose the threat with Apple remains unclear. But the fact that this attack — which in some cases can be performed remotely — was known to some developers weeks before Apple issued a statement about it is sure to turn heads.

Mashable has reached out to Apple for comment and will update the story as soon as we hear back.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You

Hackers are exploiting a vulnerability in lots of e-commerce sites
Fish-eye lens view of a computer screen with hacking stuff on it

Apple expects high demand from its March 4 releases
apple logo over a smartphone with black background


Apple plans a 'high-end' Ultra line, including iPhone Fold, report says
Apple logo on iPhone

More in Tech
T-Mobile is giving away the Apple iPhone 17 for free — how to qualify
Apple iPhone 17 on Mashable composite background

The DJI Mini 5 Pro drone is down to its best-ever price at Amazon — save $500 this weekend
DJI Mini 5 Pro Fly More Combo

California just launched the country's largest public broadband network
Newsom stands behind a teen on a computer. A group of people cheer and clap behind them.

The Shark FlexStyle is our favorite Dyson Airwrap dupe, and it's $160 off at Amazon right now
The Shark FlexStyle Air Styling & Drying System against a colorful background.

Amazon's sister site is having a one-day sale, and this Bissell TurboClean deal is too good to skip
A woman using the Bissell TurboClean Cordless Hard Floor Cleaner Mop and Lightweight Wet/Dry Vacuum.

Trending on Mashable
NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone

NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

NYT Strands hints, answers for April 4, 2026
A game being played on a smartphone.

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!