{"id":95634,"date":"2017-11-30T12:01:28","date_gmt":"2017-11-30T12:01:28","guid":{"rendered":"http:\/\/sftarticles.wpenginepowered.com\/en\/?p=95634"},"modified":"2025-07-01T23:43:16","modified_gmt":"2025-07-02T06:43:16","slug":"how-did-this-weeks-mac-vulnerability-affect-you","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/how-did-this-weeks-mac-vulnerability-affect-you\/","title":{"rendered":"How did this week&#8217;s Mac security vulnerability affect you?"},"content":{"rendered":"<p>You spend your life hearing from your Apple fanboy friends that <strong>their Macs are so much secure than your Windows PC.\u00a0<\/strong>Then, out of nowhere, a software analyst on Twitter comes along highlights the most <strong>basic security flaw. <\/strong>That&#8217;s what&#8217;s happening with MacOS Sierra.<\/p>\n<p>Apple being Apple meant it <strong>didn\u2019t take long before an official patch was released,<\/strong> but for one glorious day, all those Apple fanboys were fiddling around with unofficial fixes and flapping about the security of their glorious Macs. Let\u2019s have a look at the whole saga in a bit more detail.<\/p>\n<p><em>Our Softonic Solutions users are talking about <a href=\"https:\/\/solutions.softonic.com\/what-are-the-best-macos-apps?utm_medium=articlesen&amp;utm_source=articlesen&amp;utm_campaign=mac-root-login-vulnerability\" target=\"_blank\" rel=\"noopener noreferrer\">The 35 best MacOS apps<\/a>. Join the conversation now!<\/em><\/p>\n<h3>Nov. 28<span style=\"font-size: 17.25px\">,<\/span> 2017 \u2013 10:38AM<\/h3>\n<h5>All hell breaks loose<\/h5>\n<p><a href=\"https:\/\/twitter.com\/lemiorhan\" target=\"_blank\" rel=\"noopener noreferrer\">Lemi Orhan Ergin<\/a>, a software craftsman and analyst, highlights on Twitter a <strong>\u201c*HUGE*\u201d security issue<\/strong> that, he says, <strong>affects all Macs running MacOS Sierra<\/strong>. The vulnerability allows people to log into any Mac by <strong>entering root<\/strong> into the username, <strong>leaving the password blank<\/strong> and <strong>clicking login several times<\/strong>.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\">\n<p lang=\"en\" dir=\"ltr\">Dear <a href=\"https:\/\/twitter.com\/AppleSupport?ref_src=twsrc%5Etfw\">@AppleSupport<\/a>, we noticed a *HUGE* security issue at MacOS High Sierra. Anyone can login as &quot;root&quot; with empty password after clicking on login button several times. Are you aware of it <a href=\"https:\/\/twitter.com\/Apple?ref_src=twsrc%5Etfw\">@Apple<\/a>?<\/p>\n<p>&mdash; Lemi Orhan Ergin (@lemiorhan) <a href=\"https:\/\/twitter.com\/lemiorhan\/status\/935578694541770752?ref_src=twsrc%5Etfw\">November 28, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Other Twitter users give it a try and shriek in horror as <strong>this massive hole in their Mac\u2019s security checks out<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/pbs.twimg.com\/media\/DPvZm65W0AADZoY.jpg\" width=\"473\" height=\"365\" \/><\/p>\n<h3>Nov. 28<span style=\"font-size: 17.25px\">,<\/span> 2017 \u2013 12:25pm<\/h3>\n<h5>Apple responds<\/h5>\n<blockquote class=\"twitter-tweet\" data-width=\"550\">\n<p lang=\"en\" dir=\"ltr\">Let&#39;s take a closer look at what&#39;s happening together. Send us a DM that includes your Mac model along with your macOS version. We&#39;ll meet up with you there. <a href=\"https:\/\/t.co\/GDrqU22YpT\">https:\/\/t.co\/GDrqU22YpT<\/a><\/p>\n<p>&mdash; Apple Support (@AppleSupport) <a href=\"https:\/\/twitter.com\/AppleSupport\/status\/935605599328497664?ref_src=twsrc%5Etfw\">November 28, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The <strong>panic sets in at the new Apple HQ,<\/strong> so they get all customer service and send the <strong>most generic response ever<\/strong>. Behind the scenes, however, the \u201cgeniuses\u201d are at work, and it doesn\u2019t take them long to come up with a plan of action to calm their darling fanboys.<\/p>\n<h3>Nov. 28<span style=\"font-size: 17.25px\">,<\/span> 2017 \u2013 12:45pm<\/h3>\n<h5>The unofficial patch is released<\/h5>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-95635\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-story.jpg\" alt=\"\" width=\"847\" height=\"193\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-story.jpg 847w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-story-300x68.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-story-768x175.jpg 768w\" sizes=\"auto, (max-width: 847px) 100vw, 847px\" \/><\/p>\n<p>It doesn\u2019t take Apple long to come up with the most <a href=\"https:\/\/support.apple.com\/en-us\/HT204012\" target=\"_blank\" rel=\"noopener noreferrer\">common sense solution<\/a> to the problem. If somebody can log in to the Mac via the root account\u00a0 without entering a password,\u00a0<strong>all users have to do is change the password for the root account<\/strong>. Before long, sites like <a href=\"https:\/\/9to5mac.com\/2017\/11\/28\/how-to-set-root-password\/\" target=\"_blank\" rel=\"noopener noreferrer\">9to5mac<\/a> are running detailed tutorials on how to change the password of the root account.<\/p>\n<h3>Nov. 29, 2017 \u2013 08:17<\/h3>\n<h5>The official fix is out there<\/h5>\n<p>This is why <strong>you have to give it to Apple<\/strong>. Less than 24 hours after this huge flaw in Mac security was released on Twitter, they had an <a href=\"http:\/\/swcdn.apple.com\/content\/downloads\/31\/63\/091-51281\/58zd5ozq420busv7wne72a9vcjq2fc5rx8\/macOSUpd10.13.1Supplemental.pkg\" target=\"_blank\" rel=\"noopener noreferrer\">official patch<\/a> ready for release that <strong>closed up the potential breach<\/strong>. It was a pretty huge flaw to begin with, but <strong>the =efficiency with which they dealt with the issue is commendable<\/strong>. This Windows user isn\u2019t quite ready to call them geniuses just yet, but he gives credit where it is due and Apple deserves a bit on this one.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-95636 aligncenter\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-1024x576.jpg\" alt=\"\" width=\"549\" height=\"309\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-1024x576.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-768x433.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920-1200x675.jpg 1200w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2017\/11\/mac-2376101_1920.jpg 1920w\" sizes=\"auto, (max-width: 549px) 100vw, 549px\" \/><\/p>\n<p><strong>The patch isn\u2019t an OTA update<\/strong>, however, so if you haven\u2019t already updated your Mac, you can download the file <a href=\"http:\/\/swcdn.apple.com\/content\/downloads\/31\/63\/091-51281\/58zd5ozq420busv7wne72a9vcjq2fc5rx8\/macOSUpd10.13.1Supplemental.pkg\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a> or follow Apple\u2019s instructions <a href=\"https:\/\/support.apple.com\/en-us\/HT208315\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/p>\n<p style=\"text-align: center\">&#8211;<\/p>\n<p>Where were you when the root security vulnerability was discovered?Did you fret over the vulnerability of your Macbook\u00a0Air as you worked on that freelance project while sipping on a skinny Christmasccino down at the Starbucks? Or did you keep the faith in your genius overlords? <strong>Let us know in the comments below<\/strong> if you think this whole debacle has shaken your faith in Apple or strengthened it.<\/p>\n<p>If you&#8217;re a Windows user and you were impressed by how quickly Apple solved this problem, you might want to check out\u00a0<a href=\"https:\/\/en.softonic.com\/articles\/questions-to-ask-when-switching-from-windows-to-mac\" target=\"_blank\" rel=\"noopener noreferrer\">Questions to ask when switching from Windows to Mac<\/a>.<\/p>\n<p style=\"text-align: center\"><em>Follow me on Twitter:\u00a0<a class=\"ProfileHeaderCard-screennameLink u-linkComplex js-nav\" href=\"https:\/\/twitter.com\/PatrickDevaney_\"><span class=\"username u-dir\" dir=\"ltr\">@<b class=\"u-linkComplex-target\">PatrickDevaney_<\/b><\/span><\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You spend your life hearing from your Apple fanboy friends that their Macs are so much secure than your Windows PC.\u00a0Then, out of nowhere, a software analyst on Twitter comes along highlights the most basic security flaw. That&#8217;s what&#8217;s happening with MacOS Sierra. Apple being Apple meant it didn\u2019t take long before an official patch &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/how-did-this-weeks-mac-vulnerability-affect-you\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;How did this week&#8217;s Mac security vulnerability affect you?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9073,"featured_media":95641,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[2441],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-95634","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/95634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9073"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=95634"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/95634\/revisions"}],"predecessor-version":[{"id":328420,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/95634\/revisions\/328420"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/95641"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=95634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=95634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=95634"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=95634"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=95634"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=95634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}