Italian Teenager Uncovers 2 Zero Day Vulnerabilities in Apple OS X

Advertisement
By Manish Singh | Updated: 17 August 2015 19:14 IST

Less than a week after Apple released a set of security patches for OS X, two new vulnerabilities are being reported in its desktop operating system. An Italian teenager claims to have found two vulnerabilities, which if exploited, could give attackers remote access to the OS X computer.

Luca Todesco, an 18-year-old, has posted details on GitHub about the exploit he has created. The exploit utilises two bugs that cause a memory corruption in OS X's kernel and facilitates root access. This memory corruption can be used to bypass kernel address space layout randomisation, the mechanism which is responsible for preventing exploit codes from executing.

Advertisement

The vulnerability affects OS X Mavericks v10.9.5 to OS X Yosemite v10.10.5. OS El Capitan v10.11, which is currently in beta, isn't affected by the said vulnerabilities. Todesco says that he notified Apple a few hours before acknowledging the existence of vulnerabilities to public. "This is not due to me having issues with Apple's patch policies/time frames, as others have incorrectly reported," he told PC World.

While Todesco has released a patch called NULLGuard to resolve the vulnerabilities, we would suggest you to wait for the official patches from Apple to arrive before taking any step.

Advertisement

Apple last week along with the release of OS X Yosemite v10.10.5 - which brought stability and compatibility fixes - also released four security patches for OS X, Safari Web browser, and old generation iPhone models and old iPod models. One of the vulnerabilities that Apple patched last week was the infamous DYLD glitch, which if exploited, allowed an attacker to gain root access to the system.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi's Phones Now Let You Share Files With iPhone Models via AirDrop
  2. HP OmniBook X 14, Ultra 16 Refreshed With Nvidia RTX Spark 'Superchip'
  3. Moto G37 Power Review: Covers All the Bases and More
  4. New iPhone 18 Pro Leak Suggests It Could Arrive in These Battery Variants
  5. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  6. Asus ROG Xbox Ally X20 Unveiled With a Larger 7.4-Inch OLED Screen
  7. Huawei Nova 16, Nova 16z Debut With 50-Megapixel Camera at This Price
  8. Samsung Galaxy Fit 4 Could Debut Alongside Galaxy S26 FE
  9. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  10. Asus ROG Strix Scar 18 (2026) With 240Hz 4K Screen Showcased at Computex
  1. Asus ROG Xbox Ally X20 With Larger 7.4-Inch OLED Display Unveiled at Computex 2026
  2. ViewSonic IN05 Series ViewBoard 4K Displays Launched in India With Android 16, AI Features
  3. Asus ProArt P16, ProArt P14 and New ProArt Mini PC With Nvidia RTX Spark Unveiled at Computex 2026
  4. Computex 2026: MSI Prestige N16 Flip AI+ Announced as Company's First Nvidia RTX Spark-Powered Laptop
  5. Apple Releases New ‘Glow All Out’ Wallpaper, Apple Music Playlist Hinting at Next Week’s WWDC 2026 Theme
  6. Xiaomi's HyperOS 3 Adds AirDrop Support on Select Models With Ability to Share Files With Apple Devices
  7. iPhone 18 Pro Leak Hints at Two Battery Variants With Slightly Different Capacities
  8. Samsung Galaxy Fit 4 Launch Timeline Reportedly Leaked; May Debut Alongside Galaxy S26 FE
  9. iPhone Ultra Tipped to Launch in White Colourway; May Feature Vapour Chamber Cooling
  10. Asus ROG Edition 20 Lineup Unveiled at Computex 2026 to Commemorate 20 Years of ROG Series Products
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.