{"id":100823,"date":"2024-08-01T01:25:18","date_gmt":"2024-08-01T08:25:18","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=100823"},"modified":"2024-08-08T07:13:35","modified_gmt":"2024-08-08T14:13:35","slug":"apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/","title":{"rendered":"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-100824\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-600x300-v2.jpg\" alt=\"\" width=\"600\" height=\"300\" \/><\/p>\n<p>As we first <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-neglects-to-patch-multiple-critical-vulnerabilities-in-macos\/\">noted<\/a> in November 2023, macOS Sonoma contains some very outdated open-source software components. (Free\/libre open-source software is commonly abbreviated as FOSS or FLOSS.) This outdated software puts Mac users at serious risk. We&#8217;ve reached out to Apple multiple times about this, and Apple still hasn&#8217;t responded. Here&#8217;s what we know.<\/p>\n<h3>How did Intego notice these outdated components?<\/h3>\n<p>In October 2023, there was a lot of buzz about CVE-2023-38545, a critical vulnerability in the open-source software curl. When checking which version was included with the latest macOS Sonoma update, we <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-neglects-to-patch-multiple-critical-vulnerabilities-in-macos\/\">discovered<\/a> that curl was indeed outdated. But it wasn&#8217;t just a single version behind; curl was actually six months out of date, and was missing other security patches as well.<\/p>\n<p>The Terminal command to find out curl&#8217;s version also revealed something even worse: several of curl&#8217;s dependencies (other open-source software upon which curl relies) were also severely outdated. <strong>The most serious of these was LibreSSL, which is now nearly 29 months out of date.<\/strong><\/p>\n<p>A couple of components have been silently updated to newer versions since then. For example, in macOS Sonoma 14.5, without any mention in <a href=\"https:\/\/support.apple.com\/kb\/HT214106\" target=\"_blank\" rel=\"noopener\">Apple&#8217;s official security release notes for the OS update<\/a>, Apple upgraded curl from 8.4.0 to 8.6.0, and nghttp2 from 1.58.0 to 1.61.0. Oddly, curl 8.6.0 was, at the time, nearly two months behind on patches; it&#8217;s unclear why Apple chose not to upgrade to the latest available at the time, which was 8.7.1, given that 8.6.0 had known vulnerabilities.<\/p>\n<p>In macOS Sonoma 14.6, Apple <em>did<\/em> note curl patches in its <a href=\"https:\/\/support.apple.com\/en-us\/HT214119\" target=\"_blank\" rel=\"noopener\">release notes<\/a>. However, once again Apple upgraded curl from an old version (8.6.0) to another outdated and vulnerable version (8.7.1). Version 8.7.1 came out four months earlier and contained <a href=\"https:\/\/curl.se\/docs\/security.html\" target=\"_blank\" rel=\"noopener\">three vulnerabilities<\/a>; one was &#8220;medium&#8221; severity. The fully patched version of curl at the time of Sonoma 14.6&#8217;s release was 8.9.0.<\/p>\n<h3>Which vulnerable components does the current macOS Sonoma release include?<\/h3>\n<p>Intego is aware of at least the following vulnerabilities in <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-releases-macos-sonoma-14-6-ios-17-6-and-more-with-security-updates\/\">macOS Sonoma 14.6<\/a>, the latest version:<\/p>\n<ul>\n<li><strong>LibreSSL 3.3.6<\/strong>\u00a0is more than 2 years old and contains at least\u00a0<a href=\"https:\/\/nvd.nist.gov\/vuln\/search\/results?form_type=Advanced&amp;results_type=overview&amp;isCpeNameSearch=true&amp;seach_type=all&amp;query=cpe:2.3:a:openbsd:libressl:3.3.6:*:*:*:*:*:*:*\" target=\"_blank\" rel=\"noopener\">4 known vulnerabilities<\/a>, including two rated 9.8 CRITICAL on the CVSS scale; the latest stable release is 3.9.2, released on May 12, 2024.<\/li>\n<li><strong>curl 8.7.1<\/strong> contains at least <a href=\"https:\/\/curl.se\/docs\/vuln-8.7.1.html\" target=\"_blank\" rel=\"noopener\">2 known vulnerabilities<\/a>; the latest version is 8.9.1, released on July 31, 2024.<\/li>\n<li><strong>zlib 1.2.12<\/strong>\u00a0contains at least\u00a0<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-45853\" target=\"_blank\" rel=\"noopener\">one vulnerability with a CVE<\/a>; the latest version is 1.3.1, released on January 22, 2024.<\/li>\n<li><strong style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">nghttp2 1.61.0<\/strong><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\"> contains at least <\/span><a style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\" href=\"https:\/\/github.com\/nghttp2\/nghttp2\/pull\/2136\" target=\"_blank\" rel=\"noopener\">one known vulnerability<\/a><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">; the latest version is 1.62.1, released on May 19, 2024.<\/span><\/li>\n<\/ul>\n<p>While not included by default in macOS Sonoma, running <strong>python3<\/strong> from the command line prompts the user to install it. If the user proceeds, they will get a version 3.7.3 on an Intel Mac, or version 3.9.6 on an Apple silicon Mac. These versions are from March 25, 2019, and June 28, 2021, respectively. Both Python <a href=\"https:\/\/nvd.nist.gov\/vuln\/search\/results?isCpeNameSearch=true&amp;query=cpe%3A2.3%3Aa%3Apython%3Apython%3A3.7.3%3A*%3A*%3A*%3A*%3A*%3A*%3A*&amp;results_type=overview&amp;form_type=Advanced&amp;startIndex=0\" target=\"_blank\" rel=\"noopener\">3.7.3<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/search\/results?isCpeNameSearch=true&amp;query=cpe%3A2.3%3Aa%3Apython%3Apython%3A3.9.6%3A*%3A*%3A*%3A*%3A*%3A*%3A*&amp;results_type=overview&amp;form_type=Advanced&amp;startIndex=0\" target=\"_blank\" rel=\"noopener\">3.9.6<\/a> contain many severe vulnerabilities.<\/p>\n<p>It&#8217;s quite likely that there may be other outdated FOSS components with known vulnerabilities in the current macOS Sonoma release; we leave this as an exercise for other researchers to look into.<\/p>\n<p>So far, the beta versions of macOS Sequoia look virtually as bad as Sonoma. All of the above vulnerabilities apply to the current Sequoia beta, except one: the vulnerability in nghttp2.<\/p>\n<h3>Has Apple implemented alternative mitigations for the unpatched vulnerabilities?<\/h3>\n<p>It&#8217;s unclear whether Apple might have other mitigations in place for some of the vulnerabilities that it seems to be leaving unpatched. Or, perhaps, in some cases Apple could hypothetically be backporting patches without updating the version numbers it uses.<\/p>\n<p>Whatever the case may be, <strong>Apple has not responded to our multiple inquiries<\/strong> over the past nine months since we first tried to bring the issue to Apple&#8217;s attention.<\/p>\n<p>Security researchers with a bit of time on their hands may wish to dive more deeply and test the exploitability of these and other publicly documented vulnerabilities in macOS Sonoma&#8217;s FOSS components.<\/p>\n<h3>Why is Apple negligent in patching open-source software?<\/h3>\n<p>Notably, the ongoing issues with macOS Sonoma aren&#8217;t the first time that Apple has neglected to patch open-source software quickly in its operating systems. One well-documented public example of this was <a href=\"https:\/\/www.macrumors.com\/2022\/01\/28\/apple-removing-python-2-in-macos-12-3\/\" target=\"_blank\" rel=\"noopener\">Apple&#8217;s inclusion of Python 2.7 with macOS for nearly two years after its final update<\/a>.<\/p>\n<p>But the issue has been ongoing for at least a decade, if not longer; Rob Griffiths blogged about &#8220;<a href=\"https:\/\/robservatory.com\/behind-os-xs-modern-face-lies-an-aging-collection-of-unix-tools\/\" target=\"_blank\" rel=\"noopener\">OS X&#8217;s\u2026 aging collection of Unix tools<\/a>&#8221; in September 2014. (Griffiths speculated that Apple&#8217;s opposition to the GPLv3 software license may have explained the company&#8217;s avoidance of software post-migration to GPLv3. Even so, it does not explain why Apple is slow to update other FOSS components.)<\/p>\n<p>Such things rarely get media coverage, however. Outdated FOSS components in macOS typically go unnoticed, except amongst a small handful of researchers and engineers who pay attention to such things.<a name=\"users\"><\/a><\/p>\n<h3>What can users do about this?<\/h3>\n<p>Unfortunately, when Apple chooses not to patch known vulnerabilities quickly, it leaves end users exposed. While there&#8217;s little that Mac users can do about it, there is one important thing. You can help put pressure on Apple by raising awareness of reports like this one.<\/p>\n<p>We encourage responsible media outlets to report on issues of public concern like this, to encourage Apple to not take a lax approach to security issues.<a name=\"learnmore\"><\/a><\/p>\n<h3>How can I learn more?<\/h3>\n<p><a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><img class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\" \/><\/a>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego&#8217;s Mac security experts discuss the latest Apple news, including security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don&#8217;t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.<\/p>\n","protected":false},"author":14,"featured_media":100827,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7],"tags":[4686,143],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-01T08:25:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-08T14:13:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg\",\"width\":400,\"height\":260,\"caption\":\"Apple software update red critical urgent actively exploited zero-day vulnerability with subtle this is fine meme dog fire background\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/\",\"name\":\"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage\"},\"datePublished\":\"2024-08-01T08:25:18+00:00\",\"dateModified\":\"2024-08-08T14:13:35+00:00\",\"description\":\"Apple still hasn\\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\\u2014and the company won\\u2019t say why.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma\",\"datePublished\":\"2024-08-01T08:25:18+00:00\",\"dateModified\":\"2024-08-08T14:13:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage\"},\"wordCount\":943,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg\",\"keywords\":[\"macOS Sonoma\",\"Vulnerabilities\"],\"articleSection\":[\"Apple\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/","og_locale":"en_US","og_type":"article","og_title":"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma - The Mac Security Blog","og_description":"Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2024-08-01T08:25:18+00:00","article_modified_time":"2024-08-08T14:13:35+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg","width":400,"height":260,"caption":"Apple software update red critical urgent actively exploited zero-day vulnerability with subtle this is fine meme dog fire background"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/","name":"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage"},"datePublished":"2024-08-01T08:25:18+00:00","dateModified":"2024-08-08T14:13:35+00:00","description":"Apple still hasn\u2019t patched several critical, years-old vulnerabilities in open-source components of macOS Sonoma\u2014and the company won\u2019t say why.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"Apple still leaving critical vulnerabilities unpatched in macOS Sonoma","datePublished":"2024-08-01T08:25:18+00:00","dateModified":"2024-08-08T14:13:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#webpage"},"wordCount":943,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg","keywords":["macOS Sonoma","Vulnerabilities"],"articleSection":["Apple"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-still-leaving-critical-vulnerabilities-unpatched-in-macos-sonoma\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/06\/Apple-software-update-red-critical-urgent-this-is-fine-bg-400x260-v2.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-qeb","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/100823"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=100823"}],"version-history":[{"count":7,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/100823\/revisions"}],"predecessor-version":[{"id":101323,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/100823\/revisions\/101323"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/100827"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=100823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=100823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=100823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}