Now they're playing with the sudoers file

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
I thought the code drop was a patch for the vulnerability.

It seems unclear as to whether Esser, the discoverer of the exploit, told Apple first. If he did, and gave them time, shame on Apple. If he didn't, shame on him.
 
OP
cradom
Joined
Feb 14, 2004
Messages
4,781
Reaction score
166
Points
63
Location
Groves, Texas
It was my understanding he disclosed it first, before he told Apple. And then he came out with software to check/disable the flaw?
Not gonna download that one, no sir. I understand Apple's...um....peeved.
 

vansmith

Senior Member
Joined
Oct 19, 2008
Messages
19,924
Reaction score
559
Points
113
Location
Queensland
Your Mac's Specs
Mini (2014, 2018, 2020), MBA (2020), iPad Pro (2018), iPhone 13 Pro Max, Watch (S6)
In that case, yeah, that was a bad move. If a company does nothing? They're fair game. If a company doesn't know, they're not fair game and if you actually cared, you'd divulge things first.

Apparently the issue is non-existent in 10.11 so I guess we'll all have a fix in two months or so.
 
C

chas_m

Guest
It is also fixed in the betas for 10.10.5.

Not noted in most of the reporting on this is that you have to actually install this malware yourself, meaning you must provide your admin password. Only then can it escalate its privileges by using the error-reporting flaw. Whereupon -- it must be said -- it wastes an enormous opportunity for harm and instead simply installs a bunch of adware/junkware that is fairly easily removed (thanks to AdwareMedic/Malwarebytes). Apple is very very likely to update XProtect for older versions of Yosemite after 10.10.5 is out, but my understanding is that the flaw is limited to Yosemite, since it was introduced in the change to Yosemite's error reporting.
 

Shop Amazon


Shop for your Apple, Mac, iPhone and other computer products on Amazon.
We are a participant in the Amazon Services LLC Associates Program, an affiliate program designed to provide a means for us to earn fees by linking to Amazon and affiliated sites.
Top