Security researchers have discovered a previously unknown vulnerability in Apple's OS X 10.10 (Yosemite) operating system that could allow attackers and skilled hackers to install malware and adware on any Mac computer without administrator privileges.
The specific zero-day vulnerability (YLD_PRINT_TO_FILE) was discovered by Adam Thomas and affects the current version of Mac OS X, 10.10.4, as well as the beta version of OS X 10.10.5 Yosemite.
[signoff icon=”icon-target”]Researcher Adam Thomas says he discovered the vulnerability in Mac OS X 10.10.4 Yosemite during some testing he was doing on an adware installer, having modified the code of the sudoers files so that anyone could install any program on the target computer, without needing the user’s consent or any other password to access the system.[/signoff]
This vulnerability is due to the new error-logging feature introduced in Mac OS X 10.10 and can be exploited by attackers to install adware such as MacKeeper, VSearch, and Genieo.
Mac OS X 10.11 El Capitan is not affected
The good news for those using the Mac OS X 10.11 El Capitan Beta version of the operating system is that they are not affected by this particular attack. Other users will have to wait until Apple releases a new version of the operating system that fixes this particular security flaw.

