OS X update fixes major Yosemite security flaw

Apple OS X Yosemite

An OS X patch to Apple's Yosemite operating system released on Thursday brings a number of improvements to Mac users. The most important component of the update is the security fix, which patches the DYLD vulnerability uncovered by a security researcher last month.

"The OS X Yosemite 10.10.5 update improves the stability, compatibility, and security of your Mac, and is recommended for all users," Apple said in a statement.

Apple's patch resolves a privilege escalation flaw in OS X that allows a remote hacker to take control of a user's Mac without needing an administrator password. The Guardian reports that this flaw has already been exploited by at least one known adware.

In its release notes, Apple credited security researcher Stefan Esser for discovering the flaw, and claimed that the security issue "was addressed through improved environment sanitization," in the OS X 10.10.5 update. The patch is available for users running OS X Yosemite versions 10.10 through 10.10.4. Apple did not provide any additional details.

Other patches and fixes

In addition to fixing the privilege flaw, Apple also patched a number of security vulnerabilities in its latest OS update, including vulnerabilities related to Apple ID, Bluetooth and more. Complete details of the security patches can be found on Apple's support site.

Given the seriousness of these security flaws, Yosemite users are advised to download and install the OS X 10.10.5 update as soon as possible.

Esser, who initially discovered the DYLD vulnerability, took to Twitter to complain that there are still issues with Apple's patch.

"Hmm so Apple released 10.10.5 fixed some bugs and made another security problem worse than before," said Esser. He did not elaborate on any additional problems created by OS X 10.10.5 and has not responded to our request for comment.

Additionally, Apple's latest update also fixes issues with the Mail, Photos and QuickTime Player apps.

TOPICS
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Pedro Pascal in Apple's Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons' Homer's Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Nvidia GR00T N1 humanoid robot
Nvidia is dreaming of trillion-dollar datacentres with millions of GPUs and I can't wait to live in the Omniverse
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way