I found this article and tested it myself,
"In software, there are bugs, and there are dangerous bugs. It looks like macOS High Sierra has one of those dangerous bugs; one that could give someone full access to virtually any user account. And holy buckets, it is scary.
Turkish software developer Lemi Orhan Ergin pointed out an apparent macOS security vulnerability in a tweet on Tuesday afternoon. Basically, if you open System Preferences and then navigate to Users and Groups, you can easily gain access to make changes to any account on that machine. Just click the lock, and when macOS prompts you for a password, replace the user name with “root,” select the password field (but don’t type in a password), and click Unlock. Just like that, the system will unlock. We were able to replicate the issue multiple times. (Seven attempts seems to be the sweet spot.)"
Source:
https://gizmodo.com/theres-a-massive-security-vulnerability-in-the-new-maco-1820810018
"In software, there are bugs, and there are dangerous bugs. It looks like macOS High Sierra has one of those dangerous bugs; one that could give someone full access to virtually any user account. And holy buckets, it is scary.
Turkish software developer Lemi Orhan Ergin pointed out an apparent macOS security vulnerability in a tweet on Tuesday afternoon. Basically, if you open System Preferences and then navigate to Users and Groups, you can easily gain access to make changes to any account on that machine. Just click the lock, and when macOS prompts you for a password, replace the user name with “root,” select the password field (but don’t type in a password), and click Unlock. Just like that, the system will unlock. We were able to replicate the issue multiple times. (Seven attempts seems to be the sweet spot.)"
Source:
https://gizmodo.com/theres-a-massive-security-vulnerability-in-the-new-maco-1820810018