Google's Project Zero discloses three OS X vulnerabilities requiring access to machine; Apple's fix is still only in Yosemite's beta build
Latest OS X 10.10.2 beta kills Google-disclosed vulnerabilities dead — Google's Project Zero research program has disclosed and released proof …
Context & Ripple Effects
Google's Project Zero has published proof-of-concept code for three OS X vulnerabilities that all require local machine access, while Apple's fix exists only inside the unreleased OS X 10.10.2 Yosemite beta — meaning every Mac on a shipping build is exposed by design of the disclosure. That gap between published exploit and public patch is the story: Project Zero's fixed disclosure deadline forces Apple's patch schedule into public view.
The pattern didn't stay isolated — Google ran the same play against Apple again in 2019, disclosing a high-severity macOS kernel flaw after privately reporting it months earlier with no patch available, and mid-2015 brought both a zero-day against a fully patched OS X and a privilege-escalation bug that survived into 10.10.5.
First-order effects
- Mac users on shipping OS X Yosemite builds have working proof-of-concept code for three local-access vulnerabilities but no way to patch, since the fix lives only in the 10.10.2 beta.
- Apple faces immediate pressure to accelerate 10.10.2 out of beta, because each day the fix stays unreleased extends the window where disclosure precedes protection.
Second-order effects
- Attackers gain free, tested exploitation primitives for local privilege attacks, raising the value of the physical-access and malware-delivery chains that the August 2015 zero-day against a fully patched OS X showed were already live.
- Google demonstrated the tactic scales: its 2019 disclosure of an unpatched macOS kernel flaw repeated the same disclosure-before-patch move four years later, turning Project Zero's calendar into a standing constraint Apple must build its patch pipeline around.
Third-order effects
- If the pattern holds, coordinated disclosure stops being a courtesy exchange between researchers and vendors and becomes a public accountability mechanism — with big-company research arms like Project Zero effectively setting the patch-cadence standards for entire platforms.
- Security research also hardens as a competitive lever between platform rivals: Google's disclosures consistently land on Apple's flagship OS, entangling vulnerability handling with the broader Google–Apple platform rivalry.
The trend: Corporate research labs like Google's Project Zero are replacing quiet coordination with deadline-driven disclosure, forcing platform vendors like Apple to compress patch cycles or absorb public exposure windows.