Security Vulnerability in Mac Client Has Been Addressed
Last month, we were contacted by Pure Hacking, a group of ethical hackers in Australia, who reported what they believed to be a zero-day vulnerability in Skype for Mac 5.x. This vulnerability, which they blogged about earlier today …
Context & Ripple Effects
The fix lands hours after the disclosure cycle went public: Pure Hacking, an Australian ethical-hacking firm, blogged about what it believed was a zero-day flaw in Skype for Mac 5.x, and ZDNet's interview with the researcher framed it as 'dangerous' while Skype had yet to patch it. Skype's security team confirms it was contacted by Pure Hacking last month, meaning this is a coordinated disclosure that reached resolution the same day the details went live.
For Skype, the timing matters beyond the bug itself: the company has been in an expansion sprint all year — a new chief executive hired in January 2011, the completed Qik combination and carrier video-calling push announced in February, and Home-tab advertising launched in March — so a publicized hole in its desktop client arrives just as it is courting mainstream users and carriers.
First-order effects
- Mac users running Skype 5.x get a patched client the day the vulnerability details were published, closing the window between public disclosure and fix.
- Pure Hacking's responsible-disclosure approach — reporting last month, blogging today — is validated by Skype's acknowledgment, strengthening the firm's standing with future vendor contacts.
Second-order effects
- Other consumer VoIP and messaging vendors face the same researcher playbook applied to their own clients, since Pure Hacking demonstrated a high-profile vendor will engage and patch within a disclosure cycle.
- Skype's simultaneous push into advertising and carrier partnerships raises the stakes of client trust: any perception that its rapidly expanding Mac and mobile footprint is insecure now carries commercial cost alongside reputational cost.
Third-order effects
- If researcher attention keeps tracking consumer adoption of Mac software — a pattern visible as far back as the 2007 QuickTime zero-day coverage — cross-platform communication clients will be treated by attackers and auditors alike as first-class targets rather than Windows-only afterthoughts.
- The episode reinforces the emerging norm that vendors need standing vulnerability-response processes, since disclosure timelines are set by independent firms rather than the vendor's own release calendar.
The trend: As Mac install bases grow, independent security researchers are forcing consumer communication vendors like Skype to treat non-Windows clients as primary attack surface and patch on researcher-driven timelines.