Three Severe OS X Vulnerabilities Revealed By Google Researchers Three Severe OS X Vulnerabilities Revealed By Google Researchers

Google keeps firing shots at its competition. This time, the researchers from Google's security team called Project Zero came forward with three OS X vulnerabilities that haven't been patched yet. According to analysts, all three of these flaws pose a severe security threat and all of them have been reported to Apple back in October 2014, but the Cupertino-based company failed to fix them in time. According to the Project Zero rules, each newly found vulnerability is disclosed to the general public 90 days after its discovery, and this week the allotted time interval has expired.

The found vulnerabilities are: 

  • "OS X networked "effective_audit_token" XPC type confusion sandbox escape," - a flaw that allows hackers to bypass commands in the network system.
  • "OS X IOKit kernel code execution due to NULL pointer dereference in IntelAccelerator."
  • "OS X IOKit kernel memory corruption due to bad bzero in IOBluetoothDevice." -  a glitch that lets ill-intentioned people to exploit the OS kernel structure.

Even though the attacker will first need to have access to the Mac in order to exploit any of these vulnerabilities, they still pose a severe security threats as they enable hackers to elevate their privileges and completely take over the machine. Along with the flaws, Google's researchers also published proof-of-concept exploits, to demonstrate exactly how each of them works. Hopefully, Apple's engineers will be able to fix these issues as soon as possible.

G
Guest
Nice that google crackers have helped out NSA, with all that time for corporate espionage on their hands...

Was it helpful?  yes(0) no(0) | Reply
G
Guest
"Attackers will first need to have access to the Mac"?

Was it helpful?  yes(0) no(0) | Reply

Author's other posts

How to make your Mac kid-friendly?
Article
How to make your Mac kid-friendly?
A few tips on how to ensure your kids' safety while they're using Macs as well as on how to keep the machine safe from your children.
Samsung's next Galaxy phone is already up for reservations
News
Samsung's next Galaxy phone is already up for reservations
Even though Samsung hasn't announced the price of the upcoming Galaxy phone or its technical specifications, we can already make reservations and be among the first to receive it.
Find out which Android phones will be able to run Fortnite
News
Find out which Android phones will be able to run Fortnite
Curious to see if you'll be able to play the Android version of Fortnite on your phone? Here's the complete list of supported devices.
Mac security tricks
Article
Mac security tricks
If you don't have a lot of experience in using your Mac, here are a few tips that could keep your machine safe from various threats.