The macOS High Sierra operating system has been found to be able to activate the so-called superuser, the main administrator, who has the right to perform any operations without entering a password.
Lemi Orhan Ergin, a Turkish IT specialist, tweeted about the vulnerability.
To activate the "superuser", you need to enter the username root in the dialog box that requires a login and password (except for the login window), and leave the password field empty; then you need to press "enter" several times.
You can protect yourself from exploitation of the vulnerability by setting your own password for the root user. This can be done by turning it on according to this instruction .
The vulnerability exists both in the current system version 10.13.1 and in the beta version of the next release, 10.13.2.