Just days after patching the DYLD_PRINT_TO_FILE vulnerability with a new OS X point release, Apple's desktop operating system has been hit with yet another zero-day exploit that would allow an attacker to gain root access without using a password.
New privilege escalation exploit discovered in OS X Yosemite, also affects just-released 10.10.5. DaVinci Resolve and Fusion now officially support M1 Macs. DaVinci Resolve and DaVinci. Unfortunately I don't have Time Machine set up. I'm having a major issue with Blackmagic Design's DaVinci Resolve in 10.10.5 (which seemed to update itself? I don't remember updating and one day when I restarted DaVinci no longer works and basically crashes the entire computer when I try to use it).
Davinci Resolve Mac 10.10.5 Yosemite Version
The exploit was discovered by Italian developer Luca Todesco, who relies on a combination of attacks — Â including a null pointer dereference in OS X's IOKit — Â to drop a proof-of-concept payload into a root shell. It affects every version of OS X Yosemite, but seems to have been mitigated in OS X El Capitan, which is nearing release.
Todesco did not disclose the problem to Apple before sharing it publicly early Sunday, so it remains to be seen how quickly the company will respond.
Many computer security researchers condemn such reckless action, arguing that companies should be given time to issue patches for bugs that could harm consumers, while others have become frustrated at the slow pace of response. Apple has a somewhat checkered past with OS X security updates, but has shown improvement in recent months — Â the company patched the DYLD vulnerability less than a month after disclosure.
Davinci Resolve Mac 10.10.5 Yosemite
Apple has also taken steps to harden its operating system against attacks, announcing that OS X El Capitan would ship with a new security feature called 'rootless.' Rootless is designed to restrict third-party applications from modifying certain parts of the system — even if they are running as root — Â in a manner similar to the more aggressive sandboxing in iOS.
AppleInsider has affiliate partnerships and may earn commission on products purchased through affiliate links. These partnerships do not influence our editorial content.