Italian Teenager Uncovers 2 Zero Day Vulnerabilities in Apple OS X

Advertisement
By Manish Singh | Updated: 17 August 2015 19:14 IST

Less than a week after Apple released a set of security patches for OS X, two new vulnerabilities are being reported in its desktop operating system. An Italian teenager claims to have found two vulnerabilities, which if exploited, could give attackers remote access to the OS X computer.

Luca Todesco, an 18-year-old, has posted details on GitHub about the exploit he has created. The exploit utilises two bugs that cause a memory corruption in OS X's kernel and facilitates root access. This memory corruption can be used to bypass kernel address space layout randomisation, the mechanism which is responsible for preventing exploit codes from executing.

Advertisement

The vulnerability affects OS X Mavericks v10.9.5 to OS X Yosemite v10.10.5. OS El Capitan v10.11, which is currently in beta, isn't affected by the said vulnerabilities. Todesco says that he notified Apple a few hours before acknowledging the existence of vulnerabilities to public. "This is not due to me having issues with Apple's patch policies/time frames, as others have incorrectly reported," he told PC World.

While Todesco has released a patch called NULLGuard to resolve the vulnerabilities, we would suggest you to wait for the official patches from Apple to arrive before taking any step.

Advertisement

Apple last week along with the release of OS X Yosemite v10.10.5 - which brought stability and compatibility fixes - also released four security patches for OS X, Safari Web browser, and old generation iPhone models and old iPod models. One of the vulnerabilities that Apple patched last week was the infamous DYLD glitch, which if exploited, allowed an attacker to gain root access to the system.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. DJI Osmo Pocket 4 Debuts With 1-inch CMOS Sensor, Improved Stabilisation
  2. Vivo X300 Ultra, Vivo X300 FE Confirmed to Launch in India Soon
  3. Indian Smartphone Shipments Dropped to a Six-Year Low in Q1 2026: Report
  4. OTT Releases This Week (April 13 - April 19): Toaster, Matka King, Assi, and More
  5. Google I/O 2026: What to Expect From Google's Annual Developer Conference
  6. Samsung Galaxy A27 Renders Hint at This Notable Change to Its Display
  1. Scientists Just Created the Largest 3D Map of the Universe Ever to Study Dark Energy
  2. Honor 600 Pro and Honor 600 Key Specifications, Features Revealed via Official Listing
  3. Ethereum NFT Platform Shuts Down After Blacklove Sale Falls Through
  4. Vivo X300 FE Storage Options Leaked Alongside Live Image With Telephoto Extender Kit
  5. Indian Smartphone Shipments Dropped to Six-Year Low in Q1 2026 as Vivo Topped Market, Nothing Led Growth: Counterpoint
  6. Canva Introduces Canva AI 2.0, Brings Agentic Capabilities and Memory to Perform Design Tasks
  7. MediaTek Dimensity 9600 Pro Leak Suggests 5GHz Clock Speed, High Benchmark Scores
  8. Oppo Find X9s Pro Key Specifications Surface Online as Launch Date Draws Closer
  9. Russian-Based Crypto Exchange Grinex Halts Operation After $14 Million Hack
  10. Assassin's Creed: Black Flag Resynced Will Reportedly Release in July, Reveal Set for Next Week
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.