Proof of concept code for security flaw in Leopard and Snow Leopard posted online

OS X Snow LeopardIt isn’t daily that you get to hear of security vulnerabilities in Apple’s OS X. Even if security flaws are discovered in OS X, they are rarely exploited for malicious reasons unlike in Windows where viruses are widely available. Recently, a proof of concept code has been made available online that allows a vulnerability to be exploited in OS X 10.5 (Leopard) and 10.6 (Snow Leopard). According to DailyTech, the vulnerability is a “buffer overflow error that arises from the strtod function in the underlying Unix code used for the Mac OS.” This security flaw can allow a remote attacker to take over the system.

SecurityReason has marked this vulnerability as highly critical but it hasn’t proven to be dangerous for users ever since last June, when it was first discovered by Maksymilian Arciemowicz. Several third party software such as Google Chrome and Firefox were also vulnerable to this exploit but they’ve been patched since then.

Strange to see Apple haven’t bothered fixing this security flaw despite several updates to OS X since June 2009. Hopefully 10.6.3 might include a fix.

About the Author

Imran Hussain is the founder and editor of iThinkDifferent, which he launched in 2008 to cover Apple news, reviews, and how-to guides. He has spent over 15 years writing about iOS, macOS, and the wider Apple ecosystem, with a focus on hands-on guides - installing developer betas, troubleshooting, and walking through new features on his own devices. Based in Dubai, he also loves to cover photography, gaming, and the tech industry more broadly on his social media profiles.

Leave a comment