You can log into a Mac as root/(null)? How does a bug like that even happen?
Replying to @matthew_d_green
Rich Felker Retweeted Objective-See
By having hideous layer upon layer of IPC/RPC and no coherent priv model (ala dbus) between these dialog boxes and auth mechanisms.https://twitter.com/objective_see/status/935820712824262656 …
Rich Felker added,
0 replies
1 retweet
6 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

tl;dr od_verify_crypt_passsword rets !=0, so system updates account w/ attacker specified pw 