Italian Teenager Uncovers 2 Zero Day Vulnerabilities in Apple OS X

Advertisement
By Manish Singh | Updated: 17 August 2015 19:14 IST

Less than a week after Apple released a set of security patches for OS X, two new vulnerabilities are being reported in its desktop operating system. An Italian teenager claims to have found two vulnerabilities, which if exploited, could give attackers remote access to the OS X computer.

Luca Todesco, an 18-year-old, has posted details on GitHub about the exploit he has created. The exploit utilises two bugs that cause a memory corruption in OS X's kernel and facilitates root access. This memory corruption can be used to bypass kernel address space layout randomisation, the mechanism which is responsible for preventing exploit codes from executing.

The vulnerability affects OS X Mavericks v10.9.5 to OS X Yosemite v10.10.5. OS El Capitan v10.11, which is currently in beta, isn't affected by the said vulnerabilities. Todesco says that he notified Apple a few hours before acknowledging the existence of vulnerabilities to public. "This is not due to me having issues with Apple's patch policies/time frames, as others have incorrectly reported," he told PC World.

Advertisement

While Todesco has released a patch called NULLGuard to resolve the vulnerabilities, we would suggest you to wait for the official patches from Apple to arrive before taking any step.

Advertisement

Apple last week along with the release of OS X Yosemite v10.10.5 - which brought stability and compatibility fixes - also released four security patches for OS X, Safari Web browser, and old generation iPhone models and old iPod models. One of the vulnerabilities that Apple patched last week was the infamous DYLD glitch, which if exploited, allowed an attacker to gain root access to the system.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple Cuts Jobs Across Its Sales Organization in Rare Layoff
  2. Black Friday Sale: Check Discounts on These iPhone 16 Models on Vijay Sales
  3. iQOO 15: Everything You Need to Know Ahead of Launch in India
  4. Huawei Watch GT 6, Watch GT 6 Pro Launched in India At This Price
  5. Honor 500 Pro, Honor 500 Launched With 8,000mAh Battery: See Price
  6. Apple's First Foldable iPhone Might Be Costlier Than These Apple Products
  7. iQOO 15 Mini Launch Timeline Leaked; May Arrive With This Chipset
  8. Moto G57 Power With 50-Megapixel Sony LYT-600 Camera Launched in India
  1. Apple's First Foldable iPhone Said to Be Priced Higher Than Top-of-the-Line iPhone 17 Pro Max Variant
  2. Apple Cuts Jobs Across Its Sales Organization in Rare Layoff
  3. iQOO 15 Mini Launch Timeline Leaked; Could Be Equipped With Same Battery as Flagship iQOO 15
  4. Adobe Photoshop Chrome Extension Launched, Users Get One Year of Free Photoshop Web Access
  5. Huawei Mate 80 Pro Max With Kirin 9030 Chipset Surfaces on Geekbench Ahead of China Launch
  6. Oppo A6x Specifications Tipped Ahead of India Launch; May Get Dimensity 6300 SoC and 6,500mAh Battery
  7. NASA’s Perseverance Rover Finds Metal-Rich Rock on Mars: What You Need to Know
  8. ISS Experiment Shows Moss Spores Can Survive Harsh Space Environment
  9. Asteroid 2024 YR4: Earth Safe, but New Data Shows Small 2032 Lunar Impact Risk
  10. Stephen OTT Release Date: When and Where to Watch it Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.