Error on macOS allows creating root account without password

Recently, a bug in the latest versions of macOS High Sierra allows users to create root accounts without passwords by pressing repeatedly on the Unlock button in the options panel.

The only way for an attacker to exploit this vulnerability is when the macOS owner leaves his computer without locking the screen.

With just a few clicks, an attacker can create a root account to access the vulnerable device later. This root account can also be used to log in to vulnerable computers remotely.

  1. Microsoft and GitHub cooperated to bring Git virtual file system to macOS and Linux
  2. Change Google DNS on Mac

How it works on macOS

Step 1: Open the window depending on macOS system.

Step 2: Access Users & Groups .

Step 3: Click the lock icon in the bottom left corner of the window.

Step 4: Type "root" into the username field.

Step 5: Place your mouse cursor in the password field.

Step 6: Press Unlock several times until the user is created.

Error on macOS allows creating root account without password Picture 1

The above steps will help create a root account on a computer without a password. An attacker can use this account to log in to the victim's Mac.

It is known that this error will affect macOS High Sierra operating systems 10.13.1 and 10.13.2 Beta. Users can prevent an attacker from exploiting this vulnerability by creating a root account and creating a custom password. This operation may prevent an error from creating another root account.

Turkish software developer - Lemi Orhan Ergin discovered and posted this error on macOS early yesterday. Many other macOS users have also confirmed this problem soon. Currently, Apple is trying to fix bugs and release patches.

4.5 ★ | 2 Vote

May be interested

  • Instructions to recover Wifi password on Android without RootInstructions to recover Wifi password on Android without Root
    if you want to review the wifi password you are connected to, most of the applications require the device to be rooted. however, with the wifi wps wpa tester application, you can recover wifi password on android without root easily.
  • Use Guestfish to reset the forgotten root password for the virtual machine in qcow2 format on KVMUse Guestfish to reset the forgotten root password for the virtual machine in qcow2 format on KVM
    suppose you set a root password for the virtual machine on kvm, but forgot it. so, how to gain root access? please use guestfish to reset the root password in qcow2 format on kvm.
  • How to change Zalo password on the phoneHow to change Zalo password on the phone
    to secure zalo account, users should change the password after creating zalo account. especially the use of difficult-to-guess character sequences will increase the security of your zalo account.
  • Apple updated the password revealing patch from the Disk Utility functionApple updated the password revealing patch from the Disk Utility function
    apple has just released an emergency update for macos high sierra to fix errors that expose passwords that are encrypted in apfs format via password hint feature.
  • Enable Root account in UbuntuEnable Root account in Ubuntu
    there is a sudo command in ubuntu that allows you to perform any administrative tasks in place of root account permissions. if you use another linux favorite tool and perform any administrative tasks on it, you will feel a little forced by sudo, although you can do anything like an account. root with sudo
  • How to Open Apps as Root on MacHow to Open Apps as Root on Mac
    you can open any mac application with root permissions, as long as you have an administrator password. as always, don't use root access unless you know what you're doing, or you could cause serious errors in your application or computer.
  • How to Get Full Root Privileges in LinuxHow to Get Full Root Privileges in Linux
    the 'root' account on a computer using the linux operating system is an account with full authority. to operate commands on linux, especially commands that affect system files, we often need root access or privileged access. with great power, unlike regular usage permissions, root access should only be requested when necessary. thanks to that, important system files can avoid unwanted damage.
  • Recover the password of the 'Log On' account in windows XPRecover the password of the 'Log On' account in windows XP
    for many reasons you may lose the password of your windows login account (due to forgetting, due to unintended changes), what should you do? if the account forgets the password as administrator, the way to remove it is more complicated. you use the offline nt pas tool
  • How to fix error Error code -43 deletes the file on macOSHow to fix error Error code -43 deletes the file on macOS
    when a user deletes any file in the finder file manager on macos, an error will usually occur error code -43 cannot delete the file on the system.
  • The vulnerability on macOS 10.13 allows access to the Mac with any passwordThe vulnerability on macOS 10.13 allows access to the Mac with any password
    anyone can access the settings on the app store of the macos high sierra without the right password, and another serious vulnerability.