Google discloses a “high severity” security flaw in macOS kernel after privately reporting the flaw to Apple in November 2018; no patch available yet
Google's Project Zero team is well-known for its knack of finding security flaws in the company's own products as well as those manufactured by other firms.
Context & Ripple Effects
Project Zero's disclosure of an unpatched high-severity macOS kernel flaw follows a script the team has run for years: privately report to the vendor, wait out the deadline, publish anyway. The team did exactly this against Apple before, publishing three OS X vulnerabilities in January 2015 while Apple's fix sat only in a Yosemite beta, and applied the same pressure to Microsoft with a Windows 8.1 flaw posted after the 90-day window lapsed.
The cadence has not slowed: just last year Google published a medium-severity Microsoft Edge flaw on nearly identical terms — private report in November, public disclosure with no patch available. What makes this one sharper is the target: a kernel bug in macOS, the layer where a single flaw carries system-wide reach.
First-order effects
- Mac users are running a known, publicly documented kernel vulnerability with no Apple fix shipping yet, and attackers now have Google's research as a starting point.
- Apple faces a public countdown it did not set: the flaw was reported privately in November 2018, so the disclosure signals Google judged its own deadline met regardless of Apple's patch status.
Second-order effects
- Apple's response time becomes the benchmark other vendors are measured against, since Project Zero has already shown with Microsoft and Malwarebytes that it publishes on schedule whether or not a fix exists.
- Enterprise Mac buyers get fresh ammunition for patching-cycle demands, because a vendor whose kernel flaws surface unfixed on researcher timetables complicates security compliance claims.
Third-order effects
- If the pattern holds across the 2015 OS X, 2018 Edge, and now macOS kernel disclosures, fixed-deadline disclosure hardens into an industry norm that forces all major platform vendors to treat researcher reports as SLA-bound work items rather than discretionary queues.
- The recurring asymmetry — Google researchers auditing rivals' kernels while Apple and Microsoft have no equivalent public program — keeps raising the question of who audits the auditors' platforms, a structural tension regulators may eventually weigh in on.
The trend: Platform security is shifting toward researcher-enforced patch deadlines, with Project Zero's fixed disclosure clock becoming the de facto standard vendors must build their response processes around.