The latest version of Apple’s popular MacOS is creating a huge ripple in the security community. The operating system seems to have been released with a major vulnerability in which anyone can login to the computer as the user “root” without a password, simply by clicking the link several times. While allowing access to any account without a password is bad, allowing access to the root user is a recipe for disaster.

Root is the “super user”

In the Linux and MacOS ecosystems, the root user is the “super user.” It’s the user account that has all the power. It can do anything on the system without being challenged. If an attacker gains access to the root account of your Mac, they can do whatever they want. With this exploit, Apple has inadvertently handed it to them on a silver platter.

The easiest way to plug this loophole is to set a strong root password. You will never need to log directly into this account, so we recommend setting a strong root password that is random.


