Italian Teenager Uncovers 2 Zero Day Vulnerabilities in Apple OS X

Advertisement
By Manish Singh | Updated: 17 August 2015 19:14 IST

Less than a week after Apple released a set of security patches for OS X, two new vulnerabilities are being reported in its desktop operating system. An Italian teenager claims to have found two vulnerabilities, which if exploited, could give attackers remote access to the OS X computer.

Luca Todesco, an 18-year-old, has posted details on GitHub about the exploit he has created. The exploit utilises two bugs that cause a memory corruption in OS X's kernel and facilitates root access. This memory corruption can be used to bypass kernel address space layout randomisation, the mechanism which is responsible for preventing exploit codes from executing.

The vulnerability affects OS X Mavericks v10.9.5 to OS X Yosemite v10.10.5. OS El Capitan v10.11, which is currently in beta, isn't affected by the said vulnerabilities. Todesco says that he notified Apple a few hours before acknowledging the existence of vulnerabilities to public. "This is not due to me having issues with Apple's patch policies/time frames, as others have incorrectly reported," he told PC World.

Advertisement

While Todesco has released a patch called NULLGuard to resolve the vulnerabilities, we would suggest you to wait for the official patches from Apple to arrive before taking any step.

Advertisement

Apple last week along with the release of OS X Yosemite v10.10.5 - which brought stability and compatibility fixes - also released four security patches for OS X, Safari Web browser, and old generation iPhone models and old iPod models. One of the vulnerabilities that Apple patched last week was the infamous DYLD glitch, which if exploited, allowed an attacker to gain root access to the system.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Series Tipped to Get a Fourth Model With a 7,000mAh Battery
  2. Ek Deewane Ki Deewaniyat Is Streaming Now: Know Where to Watch It Online
  3. New Climate Report Says the Arctic Is Changing Faster Than We Can Track
  1. ISS Astronauts Celebrate Christmas in Orbit, Send Messages to Earth
  2. Arctic Report Card Flags Fast Warming, Record Heat and New Risks
  3. Battery Breakthrough Uses New Carbon Material to Boost Stability and Charging Speeds
  4. Ek Deewane Ki Deewaniyat Is Streaming Now: Know Where to Watch the Romance Drama Online
  5. Realme Neo 8 Said to Feature Snapdragon 8 Gen 5 Chipset, Could Launch Next Month
  6. Revolver Rita Is Now Streaming Online: Know Where to Watch the Tamil Action Comedy
  7. Oppo Reno 15 Series Tipped to Get a Fourth Model With a 7,000mAh Battery Ahead of India Launch
  8. Interstellar Comet 3I/ATLAS Shows Rare Wobbling Jets in Sun-Facing Anti-Tail
  9. Samsung Could Reportedly Use BOE Displays for Its Galaxy Smartphones, Smart TVs
  10. Google’s Space-Based AI Data Centre Plan Faces Collision Risks in an Increasingly Crowded Orbit
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.