OS X update fixes major Yosemite security flaw

Apple OS X Yosemite

An OS X patch to Apple's Yosemite operating system released on Thursday brings a number of improvements to Mac users. The most important component of the update is the security fix, which patches the DYLD vulnerability uncovered by a security researcher last month.

"The OS X Yosemite 10.10.5 update improves the stability, compatibility, and security of your Mac, and is recommended for all users," Apple said in a statement.

Apple's patch resolves a privilege escalation flaw in OS X that allows a remote hacker to take control of a user's Mac without needing an administrator password. The Guardian reports that this flaw has already been exploited by at least one known adware.

In its release notes, Apple credited security researcher Stefan Esser for discovering the flaw, and claimed that the security issue "was addressed through improved environment sanitization," in the OS X 10.10.5 update. The patch is available for users running OS X Yosemite versions 10.10 through 10.10.4. Apple did not provide any additional details.

Other patches and fixes

In addition to fixing the privilege flaw, Apple also patched a number of security vulnerabilities in its latest OS update, including vulnerabilities related to Apple ID, Bluetooth and more. Complete details of the security patches can be found on Apple's support site.

Given the seriousness of these security flaws, Yosemite users are advised to download and install the OS X 10.10.5 update as soon as possible.

Esser, who initially discovered the DYLD vulnerability, took to Twitter to complain that there are still issues with Apple's patch.

"Hmm so Apple released 10.10.5 fixed some bugs and made another security problem worse than before," said Esser. He did not elaborate on any additional problems created by OS X 10.10.5 and has not responded to our request for comment.

Additionally, Apple's latest update also fixes issues with the Mail, Photos and QuickTime Player apps.

TOPICS
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand