Three Severe OS X Vulnerabilities Revealed By Google Researchers Three Severe OS X Vulnerabilities Revealed By Google Researchers

Google keeps firing shots at its competition. This time, the researchers from Google's security team called Project Zero came forward with three OS X vulnerabilities that haven't been patched yet. According to analysts, all three of these flaws pose a severe security threat and all of them have been reported to Apple back in October 2014, but the Cupertino-based company failed to fix them in time. According to the Project Zero rules, each newly found vulnerability is disclosed to the general public 90 days after its discovery, and this week the allotted time interval has expired.

The found vulnerabilities are: 

  • "OS X networked "effective_audit_token" XPC type confusion sandbox escape," - a flaw that allows hackers to bypass commands in the network system.
  • "OS X IOKit kernel code execution due to NULL pointer dereference in IntelAccelerator."
  • "OS X IOKit kernel memory corruption due to bad bzero in IOBluetoothDevice." -  a glitch that lets ill-intentioned people to exploit the OS kernel structure.

Even though the attacker will first need to have access to the Mac in order to exploit any of these vulnerabilities, they still pose a severe security threats as they enable hackers to elevate their privileges and completely take over the machine. Along with the flaws, Google's researchers also published proof-of-concept exploits, to demonstrate exactly how each of them works. Hopefully, Apple's engineers will be able to fix these issues as soon as possible.

G
Guest
Nice that google crackers have helped out NSA, with all that time for corporate espionage on their hands...

Was it helpful?  yes(0) no(0) | Reply
G
Guest
"Attackers will first need to have access to the Mac"?

Was it helpful?  yes(0) no(0) | Reply

Author's other posts

How to make your Mac kid-friendly?
Article
How to make your Mac kid-friendly?
A few tips on how to ensure your kids' safety while they're using Macs as well as on how to keep the machine safe from your children.
Mac security tricks
Article
Mac security tricks
If you don't have a lot of experience in using your Mac, here are a few tips that could keep your machine safe from various threats.
Mac Mini 2018: release date, price, expectations
Article
Mac Mini 2018: release date, price, expectations
Apple hasn't updated its Mac Mini line since 2014, so many people are hoping to see a new model this year. In case you're interested, here's what to expect from Mac Mini 2018:
Microsoft Office gets a fresh look and improved searching
News
Microsoft Office gets a fresh look and improved searching
Microsoft is simplifying the command ribbon as well changing up the colors and icons for the applications included in its Office suite.