Skip to main content

Anyone can log into your Mac without your password — here’s how to fix it

Anyone using MacOS High Sierra should be on high alert. A Twitter user revealed a massive security vulnerability which allows anyone to log into your system as an administrator without valid login credentials. All a malicious user has to do is attempt to log in as “root” from the login screen, leave the password field blank, and press enter over and over until the system allows access.

Dear @AppleSupport, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as "root" with empty password after clicking on login button several times. Are you aware of it @Apple?

— Lemi Orhan Ergin (@lemiorhan) November 28, 2017

The scary news is that it’s true, or it was before Apple released a security patch. So all you need to do is open your Mac App Store and check for updates. You should see a security update available, go ahead and download that and you’re all set.  Before it was fixed, the vulnerability meant anyone could approach your iMac, MacBook, or Mac Pro and access your computer without anything more than a couple keystrokes and zero technical know-how.

Recommended Videos

Additionally, it’s never a bad idea to change your system’s root password; leaving it blank was the key to the vulnerability before it was fixed. Here’s a quick tutorial on how to do just that.

Please enable Javascript to view this content

Assuming you’re running MacOS High Sierra, we’ll teach you below how to fix the problem.

First, we’re going to open up System Preferences, open Users & Groups, select Login Options, then click the lock on the bottom left side of the window and enter your password. Next, hit Join right beside Network Account Server. This will open up a small dialog box, there you will want to click Open Directory Utility. Now we’re going to click that little lock again, and enter your password.

MacOS High Sierra Vulnerability Fix
Image used with permission by copyright holder

From here, mouse up to your Finder bar, and click Edit. From this drop-down menu click Change Root Password. This is the most important part: Pick a strong, unique password that you won’t forget.

MacOS High Sierra Vulnerability Fix
Image used with permission by copyright holder

That’s it, just an extra layer of security for your Mac, now that Apple has addressed the vulnerability with a security update.

The whole issue came to light after an industrious Twitter user pinged Apple Support’s official Twitter account for help regarding the vulnerability and from there it caught fire and spread. Twitter users from all over the world were confirming that they could replicate the vulnerability, and access their own computers without using anything more than a four-letter word.

Even though it’s fixed, this wasn’t just a minor vulnerability, like a loophole in some bit of code somewhere that only a security expert could exploit. This was a dead-simple way to break into someone else’s computer, so make sure you download and apply that patch from the Mac App Store.

Update: Apple has issued a security patch to address the issue. 

Jayce Wagner
Former Digital Trends Contributor
A staff writer for the Computing section, Jayce covers a little bit of everything -- hardware, gaming, and occasionally VR.
I tested the most popular free antivirus apps for Mac. Here are the very best
A MacBook Air is shown with the Bitdefender for Mac dashboard open.

The best free antivirus software for your Mac offers robust protection without breaking the bank. Although macOS was once an unlikely target for hackers, that's changing. As Apple computers become more popular, malware prevention is increasingly important to safeguard your personal and financial data.
Finding the best antivirus software can be challenging. While subscription prices are affordable, your budget might already be tight. Thankfully, there are several good, free malware solutions for macOS. Here are our top picks for free antivirus software for Mac, with each specially tailored to protect your Apple computer. If you use Windows, we also have a list of free antivirus software for PC.
Avast One Basic

While Avast One Basic is free and shows no ads, this powerful antivirus software still protects your Mac from malware infections, and blocks new threats before they become a problem. Perhaps more impressive is the Web Shield feature that identifies malicious downloads and prevents access to hazardous websites, halting phishing attempts and other online dangers.

Read more
I found an app that fixes macOS Sequoia’s annoying pop-ups
macOS Sequoia being introduced by Apple's Craig Federighi at the Worldwide Developers Conference (WWDC) 2024.

Years ago, back when I used Windows Vista, I got so annoyed by the constant User Account Control (UAC) pop-ups asking for permission seemingly every time I did anything that I downloaded an app that could silence them for good. Perhaps not the most sensible thing to do from a security perspective -- OK, definitely not the most sensible thing to do -- but I was a desperate man. These days, I’m getting similar vibes from macOS Sequoia.

That’s because Apple’s latest operating system will nag you about permissions on a monthly basis for anything that records your screen. Granted, it’s not as frequent as what I’d get in Windows Vista -- and these prompts were actually weekly in the macOS Sequoia beta, which caused such a blowback from users that Apple changed the frequency -- but it still feels like it’s going to be a real pain for me and a lot of users. Sure, macOS Sequoia hasn’t actually been out long enough for me to be bugged by these alerts every month yet, but I don’t want to hang around until I start pulling my hair out. I need to take action now.

Read more
Two of the best Apple Intelligence features on Mac still need work
Apple Intelligence in macOS Sequoia being used to summarize a selection of text.

Recently, Apple launched the macOS Sequoia 15.1 beta, and with it came a bunch of new Apple Intelligence features. Not everything, mind you – many of the flagship tools, like the Image Playground and Siri’s more powerful capabilities, might not debut until next year. But there’s enough Apple Intelligence here to get a feel for the new system.

Ever since the beta came out, there have been two areas of Apple Intelligence I’ve wanted to focus my attention on: Mail summaries and Apple’s suite of Writing Tools. These are some of the most fleshed-out Apple Intelligence elements that exist in macOS Sequoia right now, and also potentially two of the most useful, so it made sense to channel my efforts toward them.

Read more