Apple macOS High Sierra has a huge security flaw, and it's stupid easy to exploit

Welp.
 By 
Jack Morse
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Well this isn't good. A bug in Apple macOS High Sierra can let anyone gain admin access to a Mac. To make matters worse, once that access has been gained, an attacker can later log back into the locked device anytime.

Published to Twitter on Tuesday by software engineer Lemi Orhan Ergin, the vulnerability is alarmingly straightforward. The flaw allows someone to create a kind of phantom profile, one that can log into the Mac with admin access, but it won't show up on a real admin account.

Once the phantom account is created, a user simply needs to enter "root" as a username and, without entering a password, hit enter to unlock. Importantly, the hacker first has to have access to a unlocked computer to be able to pull this off. But still, it's bad.

Mashable confirmed this security flaw exists on macOS High Sierra 10.13.0.

Anyone looking to exploit the flaw would in most cases first need physical access to the machine while an admin is logged in. They would only need access for a few seconds, though, and then could return anytime to log in as an admin.

However, should a vulnerable machine also happen to have screen sharing turned on, it is reportedly remotely vulnerable as well.

"We are working on a software update to address this issue," explained Apple when reached for comment. "In the meantime, setting a root password prevents unauthorized access to your Mac."

Instructions to do so can be found on an Apple support page.

This story has been updated with information about remote exploitation, as well as a statement from Apple.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You



Apple expects high demand from its March 4 releases
apple logo over a smartphone with black background

Jimmy Kimmel ridicules Trump response to ICE shooting: 'How stupid do you think we are?'
Jimmy Kimmel on 'Jimmy Kimmel Live.'

More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!