New OS X 10.10.5 Privilege Escalation Vulnerability Discovered - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

New OS X 10.10.5 Privilege Escalation Vulnerability Discovered

by

Just days after Apple patched the DYLD_PRINT_TO_FILE security hole with the release of OS X 10.10.5, a developer has found a similar unpatched exploit that could allow attackers to gain root-level access to a Mac.

Luca Todesco shared information (via AppleInsider) on the "tpwn" exploit on GitHub over the weekend. It affects all versions of OS X Yosemite, including OS X 10.10.5, but does not affect OS X El Capitan.

tpwnvulnerability
Todesco did not give Apple a heads up on the vulnerability before sharing it publicly, so it is not clear when Apple will release a patch for machines running OS X Yosemite. As noted by AppleInsider, it is standard procedure (and a courtesy) for security researchers and developers to provide Apple with details on vulnerabilities before publicizing them to prevent hackers from using security holes for nefarious purposes.

According to Todesco, who has also shared what he says is a third-party fix, releasing details on the exploit is no different than releasing an iOS jailbreak, but as Engadget explains, Todesco's actions have the potential to be somewhat more harmful than a jailbreak.

Those are technically true, but they downplay the practical dangers of publishing this info. Many people aren't knowledgeable enough to try third-party safeguards or deal with the possible side effects, and jailbreaks are at least intended for semi-innocuous purposes. A 'surprise' exploit for the Mac only really serves to give attackers time that they wouldn't otherwise have.

It took Apple less than a month to release OS X 10.10.5 to fix the DYLD_PRINT_TO_ACCESS vulnerability after it was first publicized, but during the time between its discovery and the launch of the fix, an exploit using the vulnerability was discovered in the wild.

Ahead of a fix for this latest vulnerability, OS X Yosemite users can protect themselves by downloading apps solely from the Mac App Store and from trusted developers.

Top Rated Comments

145 months ago
I read somewhere that he only gave Apple a few hour's notice before releasing it. He's a scumbag. And I have to say that the writer of this article is sort of a scumbag if that screenshot is the code for the vulnerability (If this is true, sorry Juli).
The screenshot is just a proof that compiling some code and running it works. However, not giving a company any chance to release a fix is something only a complete jerk would do.
Score: 10 Votes (Like | Disagree)
145 months ago
The screenshot is just a proof that compiling some code and running it works. However, not giving a company any chance to release a fix is something only a complete jerk would do.
Perhaps he had good reasons for doing this. For example, he might have evidence that the bug is already being exploited. If true, people can immdiately use the third-party fix he pointed to rather than waiting around for Apple to fix it. After all, they sometimes takes their sweet time ('http://krebsonsecurity.com/2011/11/apple-took-3-years-to-fix-finfisher-trojan-hole/') ...

Also, I think his comparison to jailbreaks is apt. Essentially whenever a jailbreak is released, the jailbreakers publish privilege escalation bugs and a nice demo on how to exploit them.

Finally, one should keep in mind that he could just as well have sold the exploit on the black market for a fat check instead of just publishing it and then getting called "complete jerk" as a reward ...
Score: 7 Votes (Like | Disagree)
bradl Avatar
145 months ago
Front page news, surely?

Seems that it is now a race between Apple and malware writers make use of this information.
Again, this isn't of much use unless the attacker has physical or network access to your Mac. That isn't to say that this isn't any less of a vulnerability than those they've fixed, but this one also isn't something that someone can target a Mac with remotely, and instantly have root access.

tl;dr: a lot of variables have to fall into place at the right time for this to have any major impact to a single machine.

BL.
Score: 6 Votes (Like | Disagree)
bradl Avatar
145 months ago
I read somewhere that he only gave Apple a few hour's notice before releasing it. He's a scumbag. And I have to say that the writer of this article is sort of a scumbag if that screenshot is the code for the vulnerability (If this is true, sorry Juli).
close.. the screenshot is of the code being compiled by a non-root user and executed by the non-root user, showing how the privileges are escalated to become root.

Doesn't take away the fact that the guy was an idiot for releasing this the way he did.

Funnily enough, @i0n1c has a patch that can be applied to this.

BL.
Score: 6 Votes (Like | Disagree)
145 months ago
That may be true, but developers have a set of ethics (s)he should abide by.
If you want to assign developers ethics, then I guess you should start by mentioning the OS developers' ethics (meaning, Apple's). Apple:

* doesn't offer bug bounties
* sometimes doesn't even react to the bug reports
* when there's a reaction it uses to take months or more (and still some people praise them!?)
* doesn't always acknowledge the bug reporter
* doesn't EVEN make it easy to report and track bugs

So, again, what developer ethics are you talking about?
Score: 5 Votes (Like | Disagree)
bradl Avatar
145 months ago
For the average user? Sure. But I know at least one university that is very nervous about their multiple computer labs full of iMacs. It's a pretty big deal.
That's my point. If deployed in a lab, university, or enterprise environment, this could be severe. All it takes is compiling it one place for one type of architecture for it to be distributed to any other Mac.

However, in a lab or Enterprise environment, where it is mainly iMacs, they aren't going to be as portable. So Find My Mac wouldn't really need to be enabled on those, so the Guest Account wouldn't need to be enabled, allowing unfetted, password-free access to the iMac. If tied to some sort of Directory protocol (Active Directory, LDAP, etc.), such work could be traced to the person that released it. So while it may be a big deal, that university could easily bait this as a trap for the malevolent user.

That security researcher doesn't owe you or the richest company in the world anything. He's free to do whatever he wants.
That may be true, but developers have a set of ethics (s)he should abide by. He is showing a complete lack of ethics in the way that he released this. On every security list I have been on (including Secunia and Bugtraq) the discoverer of the vulnerability always would let the vendor know of the vulnerability and give them time to patch it before announcing the vulnerability. Even the JB teams here (TaIG, Pangu, evad3rs) do that. This guy did not.

If you think that is fair for him to do, perhaps you should reexamine your ethics as well.

BL.
Score: 4 Votes (Like | Disagree)

Popular Stories

Home Hub Command Center with Dome Base Feature

Apple Smart Home Hub to Feature iMac G4-Style Design

Wednesday September 30, 2026 4:36 am PDT by
Apple's long-rumored smart home hub will have an iMac G4-style design and a host of unique features, Bloomberg's Mark Gurman reports. The smart home hub is said to feature a square 6-inch display, with variants that can be placed on a countertop or mounted on a wall. It features a single FaceTime camera on the front, with microphones and speakers in its connected base. Gurman described the...
HomePod minis on gradient feature 1 1

Three New Apple Smart Home Products Coming on October 13

Wednesday September 30, 2026 4:04 am PDT by
Apple plans to introduce a series of new smart home products on Tuesday, October 13, according to Bloomberg's Mark Gurman. Apple reportedly plans to debut its long-awaited smart home hub device, a new HomePod mini, and a new Apple TV on the date. The new HomePod mini and Apple TV are set to retain their existing designs, but tout faster chips to support Siri AI. The new HomePod mini will...
iPhone Duo Open

iPhone Duo Reportedly Facing Production Problems Ahead of Launch

Tuesday September 29, 2026 6:16 am PDT by
The iPhone Duo is reportedly facing production difficulties ahead of its October launch, with early output expected to be limited. A person said to be close to Foxconn's supply chain told China's Jiemian News that final assembly yields for Apple's first foldable iPhone were only slightly above 60% as of September 17. The source said that, under Apple's current quality standards, it could...
Latest Stories
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
3 hours ago
Apple Shares Photos Shot on iPhone Duo
Apple Shares Photos Shot on iPhone Duo
4 hours ago
Apple Says iPhone Duo Has Replaceable 'Cover Layer' Above the Display
Apple Says iPhone Duo Has Replaceable 'Cover Layer' Above the Display
5 hours ago
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
7 hours ago
Apple TV Just Updated Its Selection of 'Bonus' Movies
Apple TV Just Updated Its Selection of 'Bonus' Movies
9 hours ago
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
9 hours ago
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
9 hours ago
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
10 hours ago
Apple's All-New Home Hub Rumored to Launch in These Four Colors
Apple's All-New Home Hub Rumored to Launch in These Four Colors
11 hours ago
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
12 hours ago
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
13 hours ago
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
13 hours ago
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
14 hours ago
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
14 hours ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
1 day ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
1 day ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
1 day ago
Apple Event on October 13?
Apple Event on October 13?
1 day ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
1 day ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
1 day ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
1 day ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
1 day ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
2 days ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
2 days ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
2 days ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
2 days ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
2 days ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
2 days ago
AirPods 5 Teardown: Batteries Removable, Case Still Tough
AirPods 5 Teardown: Batteries Removable, Case Still Tough
2 days ago
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
2 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors