News broke Nov. 28 on Twitter that an attacker could gain root-user access to an unlocked computer simply by typing "root" into the "User Name" field, leaving the password field blank, and hitting "enter" while in the "Users & Groups" section of "System Preferences."
You can access it via System Preferences>Users & Groups>Click the lock to make changes. Then use "root" with no password. And try it for several times. Result is unbelievable! pic.twitter.com/m11qrEvECs