Italian Teenager Uncovers 2 Zero Day Vulnerabilities in Apple OS X

Advertisement
By Manish Singh | Updated: 17 August 2015 19:14 IST

Less than a week after Apple released a set of security patches for OS X, two new vulnerabilities are being reported in its desktop operating system. An Italian teenager claims to have found two vulnerabilities, which if exploited, could give attackers remote access to the OS X computer.

Luca Todesco, an 18-year-old, has posted details on GitHub about the exploit he has created. The exploit utilises two bugs that cause a memory corruption in OS X's kernel and facilitates root access. This memory corruption can be used to bypass kernel address space layout randomisation, the mechanism which is responsible for preventing exploit codes from executing.

The vulnerability affects OS X Mavericks v10.9.5 to OS X Yosemite v10.10.5. OS El Capitan v10.11, which is currently in beta, isn't affected by the said vulnerabilities. Todesco says that he notified Apple a few hours before acknowledging the existence of vulnerabilities to public. "This is not due to me having issues with Apple's patch policies/time frames, as others have incorrectly reported," he told PC World.

Advertisement

While Todesco has released a patch called NULLGuard to resolve the vulnerabilities, we would suggest you to wait for the official patches from Apple to arrive before taking any step.

Advertisement

Apple last week along with the release of OS X Yosemite v10.10.5 - which brought stability and compatibility fixes - also released four security patches for OS X, Safari Web browser, and old generation iPhone models and old iPod models. One of the vulnerabilities that Apple patched last week was the infamous DYLD glitch, which if exploited, allowed an attacker to gain root access to the system.

 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Will Go on Sale in Bengaluru at a Drop Event on This Date
  2. Oppo Find N6 Appears at MWC 2026 Ahead of Showcase; March Launch Confirmed
  3. Xiaomi 18 Series Leak Suggests Major Camera Upgrades Over Predecessor
  4. OnePlus 15T Details Revealed; New Telephoto Lens, Bigger Battery Confirmed
  5. iQOO Z11x 5G Will Launch in India on This Date
  6. Here's When the Oppo K14 5G Will Launch in India: See Expected Specs
  1. NASA’s Carruthers Observatory Begins Mission to Study Earth’s Hydrogen Halo
  2. MacBook Pro (2026) Launched in India With M5 Pro, M5 Max Chips, Up to 16-Inch Display: Price, Specifications
  3. MacBook Air With M5 Chip, Up to 15.3-Inch Display Launched in India
  4. Capcom Spotlight Livestream Announced for This Week; Will Feature Pragmata, Mega Man: Dual Override and More
  5. Tanvi The Great Now Streaming on Prime Video: An Inspiring Autistic Hero’s Journey
  6. Aspirants Season 3 OTT Release Date Announced: When and Where to Watch it Online?
  7. Samsung Announces ‘Holi Hai’ Sale With Cashback on Bespoke AI Appliances
  8. Kiss of the Spider Woman OTT Release Date: Know When and Where to Watch it Online
  9. Vanchana OTT Release: When and Where to Watch the Courtroom Drama
  10. Xiaomi 18, Xiaomi 18 Pro, Xiaomi 18 Pro Max Early Leak Reveals Rear Camera Details
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.