{"id":44092,"date":"2015-07-22T09:04:04","date_gmt":"2015-07-22T16:04:04","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=44092"},"modified":"2024-05-20T11:49:36","modified_gmt":"2024-05-20T18:49:36","slug":"yosemite-zero-day","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/","title":{"rendered":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-44104\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-600.jpeg\" alt=\"OS X Yosemite vulnerability\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-600.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-600-150x75.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-600-300x150.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>A German security researcher, Stefan Esser, has published details of a zero-day vulnerability in OS X that could allow a malicious hacker to escalate their privileges, opening opportunities for them to hijack complete control of innocent users&#8217; Macs.<\/p>\n<p>And despite releasing the details of this latest OS X security hole without informing Apple beforehand, Esser seems to have no regrets.<\/p>\n<p>To be nerdy for a second, the security flaw appears to lie in new features introduced in OS X Yosemite and the upcoming OS X El Capitan, and relate to how Apple altered its dynamic linker code\u00a0in\u00a0OS X 10.10 to support the new DYLD_PRINT_TO_FILE environment variable.<\/p>\n<p>Whilst not considered as critical as remote code execution vulnerabilities, privilege escalation bugs are still serious \u2014\u00a0a malicious hacker who has already broken into a computer system can use the exploit to give themselves system-level powers.<\/p>\n<p>Esser published full details of the security hole, including proof-of-concept exploit code, on his blog.<\/p>\n<p>The proof-of-concept code Esser has published is, he warns, dangerous because it installs a root shell onto Mac computers. For understandable reasons, we won&#8217;t link directly to it from this article.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-44095\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/poc-code.jpeg\" alt=\"Proof of concept code\" width=\"600\" height=\"344\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/poc-code.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/poc-code-150x86.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/poc-code-300x172.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Stefan Esser works for security audit firm SektionEins, and has previously found numerous software vulnerabilities, as well as analysing the so-called <a title=\"Link to description of UnFlod Baby Panda\" href=\"https:\/\/grahamcluley.com\/2014\/04\/unflod-baby-panda-iphone-malware\/\" target=\"_blank\" rel=\"nofollow noopener\">&#8220;UnFlod Baby Panda&#8221; malware<\/a> that targeted jailbroken iPhones and iPads.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-44116\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/frosty-apple-170.jpeg\" alt=\"Frosty Apple\" width=\"170\" height=\"200\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/frosty-apple-170.jpeg 170w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/frosty-apple-170-127x150.jpeg 127w\" sizes=\"auto, (max-width: 170px) 100vw, 170px\" \/><\/p>\n<p>But what has really helped give Stefan Esser \u2014\u00a0also known as i0n1c \u2014\u00a0a name for himself are the flaws he has found in Apple&#8217;s software, and his low opinion of the quality of Apple security.<\/p>\n<p>I think it would be fair to say that Apple and Esser have a frosty relationship.<\/p>\n<p>Just take a glance at the posts Esser made on his <a title=\"Link to Twitter account for Stefan Esser\" href=\"https:\/\/twitter.com\/i0n1c\" target=\"_blank\" rel=\"nofollow noopener\">his Twitter account<\/a> after he announced the flaw if you don&#8217;t believe me:<\/p>\n<blockquote><p>&#8220;Imagine how much money one could make if Apple cared about security and paid bug bounties&#8230;&#8221;<\/p>\n<p>&#8220;No need to smoke pipes to get root on OS X&#8221;<\/p>\n<p>&#8220;Same exploit should work btw on *jailbroken* iOS 8 iPhones to get root from mobile user.&#8221;<\/p>\n<p>&#8220;Of course there are the usual comments like: &#8220;why didn&#8217;t you contact Apple?&#8221; &#8211; feel free to work for free and do it yourself.&#8221;<\/p><\/blockquote>\n<p>Esser&#8217;s full disclosure certainly isn&#8217;t popular with everyone, including participants in a <a title=\"Link to Reddit thread\" href=\"https:\/\/www.reddit.com\/r\/netsec\/comments\/3e34i2\/os_x_1010_dyld_print_to_file_local_privilege\/ctb2b4y\" target=\"_blank\" rel=\"nofollow noopener\">Reddit thread<\/a> about his publishing of the flaw.<\/p>\n<p>Take this response, for instance, from Reddit&#8217;s yepthatguy2:<\/p>\n<blockquote><p>It&#8217;s not about Apple. It&#8217;s about people who happen to use Apple&#8217;s products. The publication of this vulnerability doesn&#8217;t hurt Apple (much). It mostly just hurts users.<\/p>\n<p>And if your answer is &#8220;That&#8217;s your fault for using Apple&#8217;s products&#8221;, then please direct me to the computer system that has zero security holes.<\/p><\/blockquote>\n<p>Meanwhile, back on Twitter, Esser proved himself to be unrepentant when quizzed about <a title=\"Link to Twitter conversation\" href=\"https:\/\/twitter.com\/landaire\/status\/623538075491282944\" target=\"_blank\" rel=\"nofollow noopener\">why he hadn&#8217;t emailed Apple&#8217;s security team<\/a> about the flaw:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-44098\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/twitter-exchange.jpeg\" alt=\"Twitter exchange\" width=\"600\" height=\"527\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/twitter-exchange.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/twitter-exchange-150x131.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/twitter-exchange-300x263.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-44119\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/el-capitan-170.jpeg\" alt=\"El Capitan\" width=\"170\" height=\"170\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/el-capitan-170.jpeg 170w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/el-capitan-170-150x150.jpeg 150w\" sizes=\"auto, (max-width: 170px) 100vw, 170px\" \/>But what has really got the security researcher&#8217;s goat is the discovery that the beta version of Apple&#8217;s upcoming version of OS X, El Capitan, does *not* have the same bug.<\/p>\n<p>In Esser&#8217;s view, this is a sign of the company&#8217;s irresponsible behaviour\u00a0\u2014 working on a vulnerability fix that\u00a0was shipped with the El Capitan beta in June, but apparently not bothering to backport it for the latest official version of OS X.<\/p>\n<blockquote><p>So Apple was informed about said bug months ago and as usual did the irresponsible to fix it for some beta half a year in the future only.<\/p>\n<p>Apple is indeed worse than Adobe.<\/p>\n<p>So Apple has working fix + released it in June with El Capitan beta, but did not backport. Has intention to fix in September.<\/p><\/blockquote>\n<p>To mitigate the threat, Esser&#8217;s firm SektionEins has released a kernel extension that protects computers by &#8220;stopping all DYLD_ environment variables form being recognized by the dynamic linker for SUID root binaries.&#8221;<\/p>\n<p>The source code of that tool can be <a title=\"Link to SUIDGuard\" href=\"https:\/\/github.com\/sektioneins\/SUIDGuard\" target=\"_blank\" rel=\"nofollow noopener\">downloaded from GitHub<\/a>.<\/p>\n<p>I guess we should be grateful that, at the very least, an unofficial fix has been in released alongside details of how to exploit the flaw \u2014\u00a0but it&#8217;s clear that the vast majority of Mac users will not use it.<\/p>\n<p>Let&#8217;s all hope that Apple responds appropriately, with a security update for all affected OS X users. And yes, I mean those of us using the latest version of OS X Yosemite.<\/p>\n<p><strong>Was Stefan Esser and his company SektionEins right to publish details of the vulnerability without informing Apple privately first? Would a co-ordinated disclosure of the flaw have been safer for the Apple community? Or is Esser performing a valuable service that keeps Apple&#8217;s engineers on their toes?<\/strong><\/p>\n<p>Leave a comment with your point of view below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn&#8217;t issued a patch for OS X Yosemite users.<\/p>\n<p>Should you be concerned that a security researcher has now published proof-of-concept exploit code?<\/p>\n","protected":false},"author":34,"featured_media":44125,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[151,13,5],"tags":[3151,168,2269,1435,589,2410,144,982],"class_list":["post-44092","post","type-post","status-publish","format-standard","has-post-thumbnail","category-recommended","category-security-privacy","category-security-news","tag-apple","tag-os-x","tag-el-capitan","tag-yosemite","tag-proof-of-concept","tag-stefan-esser","tag-vulnerability","tag-zero-day"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn&#039;t issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Graham Cluley\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\" \/>\n\t\t<meta property=\"og:description\" content=\"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn&#039;t issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2015-07-22T16:04:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-05-20T18:49:36+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn&#039;t issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#blogposting\",\"name\":\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\",\"headline\":\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2015\\\/07\\\/zeroday-400.jpeg\",\"width\":400,\"height\":260},\"datePublished\":\"2015-07-22T09:04:04-07:00\",\"dateModified\":\"2024-05-20T11:49:36-07:00\",\"inLanguage\":\"en-US\",\"commentCount\":10,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#webpage\"},\"articleSection\":\"Recommended, Security &amp; Privacy, Security News, Apple, OS X, OS X El Capitan, OS X Yosemite, Proof of Concept (PoC), Stefan Esser, Vulnerability, Zero Day, Graham Cluley\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#listItem\",\"name\":\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#listItem\",\"position\":3,\"name\":\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/\",\"name\":\"Graham Cluley\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2237317b8942db4407872d4d6f8d61b4aa8f152370c257894dff14ed15a0c7da?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Graham Cluley\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/\",\"name\":\"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\",\"description\":\"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn't issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2015\\\/07\\\/zeroday-400.jpeg\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#mainImage\",\"width\":400,\"height\":260},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/yosemite-zero-day\\\/#mainImage\"},\"datePublished\":\"2015-07-22T09:04:04-07:00\",\"dateModified\":\"2024-05-20T11:49:36-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability<\/title>\n\n","aioseo_head_json":{"title":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","description":"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn't issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#blogposting","name":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","headline":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-400.jpeg","width":400,"height":260},"datePublished":"2015-07-22T09:04:04-07:00","dateModified":"2024-05-20T11:49:36-07:00","inLanguage":"en-US","commentCount":10,"mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#webpage"},"articleSection":"Recommended, Security &amp; Privacy, Security News, Apple, OS X, OS X El Capitan, OS X Yosemite, Proof of Concept (PoC), Stefan Esser, Vulnerability, Zero Day, Graham Cluley"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#listItem","name":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#listItem","position":3,"name":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/","name":"Graham Cluley","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/2237317b8942db4407872d4d6f8d61b4aa8f152370c257894dff14ed15a0c7da?s=96&d=mm&r=g","width":96,"height":96,"caption":"Graham Cluley"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/","name":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","description":"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn't issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2015\/07\/zeroday-400.jpeg","@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#mainImage","width":400,"height":260},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/#mainImage"},"datePublished":"2015-07-22T09:04:04-07:00","dateModified":"2024-05-20T11:49:36-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","og:description":"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn't issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?","og:url":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/","article:published_time":"2015-07-22T16:04:04+00:00","article:modified_time":"2024-05-20T18:49:36+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","twitter:description":"Apple fixed a serious vulnerability in the beta of OS X El Capitan, but hasn't issued a patch for OS X Yosemite users. Should you be concerned that a security researcher has now published proof-of-concept exploit code?","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"44092","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 16:44:20","created":"2026-09-03 16:44:20","updated":"2026-09-04 14:09:23","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tApple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Apple Criticised for Not Patching OS X Yosemite Zero-Day Vulnerability","link":"https:\/\/www.intego.com\/mac-security-blog\/yosemite-zero-day\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/44092","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=44092"}],"version-history":[{"count":23,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/44092\/revisions"}],"predecessor-version":[{"id":100678,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/44092\/revisions\/100678"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/44125"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=44092"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=44092"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=44092"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}