An OS X vulnerability could allow someone to hijack your Mac

MacBook and OS X

A researcher uncovered a security exploit in Apple's latest OS X operating system that allows your Mac to grant privilege escalation to attackers. In turn, attackers can gain control and hijack your Mac.

The exploit affects systems running OS X Yosemite. Security researcher Stephan Esser discovered that the vulnerability was not present in the early OS X 10.11 El Capitan betas, but remains unpatched in OS X10.10.4 and the beta of OS X 10.10.5, so it remains unclear if Apple is aware of this vulnerability.

The vulnerability is the result of the way that errors are logged in OS X.

Changes to OS X that enables the vulnerability

Apple made changes to the dynamic linker dyld with the release of OS X Yosemite, allowing the DYLD_PRINT_TO_FILE to write errors to an arbitrary file.

Under normal circumstances, the dynamic linker would reject environmental variables passed to it for restricted files, but Apple didn't implement any safeguards in Yosemite. Because there are no restrictions, dyld will accept the error logging files, even for restricted root binaries.

The result, if exploited, would give hackers easy privilege escalation in Yosemite to hijack your Mac and take over control of your system.

The fix

Esser says that the vulnerability is no longer present in OS X 10.11 beta, but that the patch may have been accidental on Apple's part.

A fix for this vulnerability has been created by Esser, which you can download and install if you don't want to wait for Apple to release an official patch. The fix has been posted to GitHub.

TOPICS
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)