
After back to back revelation of highly critical vulnerabilities in Microsoft products, its time now that Google has targeted Apple to take down the security aspect people look for in Apple products. Google's Project Zero Initiative have exposed 3 Zero-Day vulnerabilities in Apple's OS X operating system, in mere 2 days of time.
The alleged reports contain detailed information including the proof-of-concept, whose code is written by Ian Beer, a member of Google's Project Zero Team.
According to the reports, these vulnerabilities were already reported to Apple as on October 20, October 21, and October 23. As the 90 day deadline expired this week, the reports have been disclosed publicly by Project Zero team.
First Zero-Day Vulnerability
OS X networkd effective_audit_token XPC type confusion sandbox escape.
The vulnerability was successfully said to be tested on OS X Mavericks 10.9.5, but it might have been fixed in OS X Yosemite 10.10.
"networkd is the system daemon which implements the com.apple.networkd XPC service. It's unsandboxed but runs as its own user. com.apple.networkd is reachable from many sandboxes including the Safari WebProcess and ntpd (plus all those which allow system-network), reads the advisory published by Google for the issue. networkd parses quite complicated XPC messages and there are many cases where xpc_dictionary_get_value and xpc_array_get_value are used without subsequent checking of the type of the returned value.
Second Zero-Day Vulnerability
OS X IOKit kernel code execution due to NULL pointer dereference in IntelAccelerator
The Second vulnerability is an IOKit kernel code execution vulnerability caused by "Null Pointer derference in IntelAccelerator. Initially Beer believed this bug to be fixed in OS X Yosemite, but later he clarified this bug to be present in OS X version 10.10.
Third Zero-Day Vulnerability
OS X IOKit kernel memory corruption due to bad bzero in IOBluetoothDevice
This flaw contains the involvement of IOSBluetoothDevice class and hence can only be exploited with Bluetooth device being connected to the target computer. The exploit has been tested with an Apple Bluetooth keyboard, Beer said.
For the time being, Google believes 90 days is more than enough time for a vendor to fix a security hole, so the company is sticking to its policy.
Over the past two months, Google's Project Zero team is on a spree of exposing vulnerabilities in products of its major Rivals, Microsoft and Apple. From past month till now, 3 highly critical vulnerabilities have been exposed by Google's Project Zero Initiative.