macOS High Sierra's App Store System Preferences Can Be Unlocked With Any Password [Updated]

A bug report submitted on Open Radar this week has revealed a security flaw in the current version of macOS High Sierra that allows the App Store menu in System Preferences to be unlocked with any password.

mac app store preferences
MacRumors is able to reproduce the issue on macOS High Sierra version 10.13.2, the latest public release of the operating system, on an administrator-level account by following these steps:

• Click on System Preferences.
• Click on App Store.
• Click on the padlock icon to lock it if necessary.
• Click on the padlock icon again.
• Enter your username and any password.
• Click Unlock.

As mentioned in the radar, we can confirm that the App Store preferences login prompt does not accept an incorrect password with a non-administrator account, meaning there is no behaviour change for standard user accounts.

We also weren't able to bypass any other System Preferences login prompts with an incorrect password, with any type of account, so more sensitive settings such as Users & Groups and Security & Privacy are not exposed by this bug.

Apple has fixed the bug in the latest beta of macOS 10.13.3, which currently remains in testing and will likely be released at some point this month. The bug doesn't exist in macOS Sierra version 10.12.6 or earlier.

On the current macOS 10.13.2, the bug gives anyone with physical, administrator-level access to a Mac the ability to disable settings related to automatically installing macOS software, security, and app updates.

This is the second password-related bug to affect macOS High Sierra in as many months, following a major security vulnerability that enabled access to the root superuser account with a blank password on macOS High Sierra version 10.13.1 that Apple fixed with a supplemental security update.

Following the root password vulnerability, Apple apologized in a statement and added that it was "auditing its development processes to help prevent this from happening again," so this is a rather embarrassing mishap.

We greatly regret this error and we apologize to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better. We are auditing our development processes to help prevent this from happening again.

It's worth noting that the App Store preferences are unlocked by default on administrator accounts, and given the settings in this menu aren't overly sensitive, this bug is not nearly as serious as the earlier root vulnerability.

Apple will likely want to fix this bug sooner rather than later, so it's possible we'll see a similar supplemental update released at some point, or perhaps it will fast track the release of macOS High Sierra version 10.13.3. Apple did not immediately respond to our request for comment on this matter.

In the meantime, if you keep your App Store preferences behind lock, you'll want to be more diligent in ensuring that you log out of your administrator account when you are away from your Mac. Alternatively, until macOS 10.13.3 is released, users can use a standard account rather than an administrator one.

While this bug isn't as dangerous as the root password vulnerability, being able to bypass a login prompt with any password is something that obviously shouldn't be possible and is an embarrassing oversight for Apple.

Related Forum: macOS High Sierra

Popular Stories

apple wallet drivers license feature iPhone 15 pro

Apple Plans to Expand iPhone Driver's Licenses to These 7 U.S. States

Thursday January 2, 2025 6:45 am PST by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Below, we outline which U.S. states and territories offer the feature, and additional states that have committed to rolling it out in...
Generic iOS 18

Here's What's New in iOS 18.3 So Far

Friday January 3, 2025 11:58 am PST by
iOS 18.3 is currently in beta for developers and public beta testers. So far, the upcoming iPhone software update is very minor in scope. Below, we outline what is new in iOS 18.3 so far. The only potential new feature coming to iPhones with iOS 18.3 so far is robot vacuum support in the Home app, but this functionality is not yet live. Apple is laying the groundwork for the feature,...
iPhone 17 Slim Feature Single Camera 1 Redux

iPhone 17 Air's Thickness and Price Range Revealed in New Report

Friday January 3, 2025 7:16 am PST by
Apple is widely rumored to be planning an ultra-thin iPhone 17 model for release later this year, and a new report offers a few purported details. South Korea's Sisa Journal today reported that Apple is aiming for the so-called "iPhone 17 Air" to be 6.25mm thick. If that measurement ends up being accurate, the device would become the thinnest iPhone ever, topping the current 6.9mm record set ...
MacBook Air 15 Inch Feature Purple

New MacBook Air Models Coming Soon With These Rumored Features

Thursday January 2, 2025 6:42 am PST by
One of Apple's first product announcements of 2025 will likely be updated 13-inch and 15-inch MacBook Air models with the M4 chip. Below, we recap rumors about the next MacBook Air models. New Features Expected The new MacBook Air models are expected to be equipped with Apple's already-released M4 chip, which has a 10-core CPU and a 10-core GPU. Apple already updated the MacBook...
Apple Intelligence General Feature

Here's What's Changing With Siri in 2025

Friday January 3, 2025 2:52 pm PST by
Apple started making Siri more capable with Apple Intelligence features in iOS 18.1 and iOS 18.2, but there are additional Siri updates that are set to come in 2025 with iOS 18 and iOS 19. By this time next year, Siri should be much smarter, if Apple's planned changes live up to what the company says is coming. Features Coming in iOS 18 The best new Siri features haven't been added yet,...
maxresdefault

Review: Apple's M4 Mac Mini is the Best Desktop Mac

Friday January 3, 2025 10:47 am PST by
Apple refreshed the Mac mini back in November, adding M4 chips and increasing the base memory. We did a hands-on impressions video at the time, but we thought we'd follow that up with a more in-depth review now that we've had more time to spend with Apple's cheapest desktop machine. Subscribe to the MacRumors YouTube channel for more videos. Priced starting at $599, the Mac mini offers the...
iPhone 17 Pro Dual Tone Rectangle Slimmer Feature 1

iPhone 17 Said to Feature More Seamless Camera Bump Design

Monday January 6, 2025 2:56 am PST by
The design of this year's next-generation iPhone 17 will allegedly feature a smoother transition between the edges of the device and the back cover, owing to Apple's use of a new glass-and-metal splicing material process. That's according to the Weibo-based leaker Fixed Focus Digital. In a post on Monday, the Chinese leaker claimed that suppliers say the iPhone 17 is adopting a "process...

Top Rated Comments

Crosscreek Avatar
91 months ago
Oh Apple....Lol

It just works....for anybody.
Score: 99 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
91 months ago
THIS WILL BE THE END OF THE WORLD!

WHAT HAS HAPPENED TO APPLE LATELY!? IF SOMEONE HAD ACCESS TO MY MACHINE THEY COULD CHANGE A COUPLE FAIRLY MEANINGLESS APP STORE PREFERENCES!!!!
Score: 42 Votes (Like | Disagree)
shareef777 Avatar
91 months ago
Passwords: now optional!
Score: 42 Votes (Like | Disagree)
Darryl.Jenks Avatar
91 months ago
Wow. Just wow.
Score: 37 Votes (Like | Disagree)
techno-Zen Avatar
91 months ago
Unreal, maybe focus less on retail store trees and more on stuff like this
Score: 33 Votes (Like | Disagree)
Chupa Chupa Avatar
91 months ago
A tad bit disturbing because it's so blatant and Apple has stated security is a feature of its products. These type of basic omissions belie its claims. Feels like Mac OS is becoming Windows with all these security patch updates. Maybe Apple needs to slow down here a bit and get back to basics.
Score: 30 Votes (Like | Disagree)