About the security content of OS X Yosemite v10.10.1

This document describes the security content of OS X Yosemite v10.10.1.

For the protection of our customers, Apple does not disclose, discuss, or confirm security issues until a full investigation has occurred and any necessary patches or releases are available. To learn more about Apple Product Security, see the Apple Product Security website.

For information about the Apple Product Security PGP Key, see How to use the Apple Product Security PGP Key.

Where possible, CVE IDs are used to reference the vulnerabilities for further information.

To learn about other Security Updates, see Apple Security Updates.

OS X Yosemite v10.10.1

  • CFNetwork

    Available for: OS X Yosemite v10.10

    Impact: Website cache may not be fully cleared after leaving private browsing

    Description: A privacy issue existed where browsing data could remain in the cache after leaving private browsing. This issue was addressed through a change in caching behavior.

    CVE-ID

    CVE-2014-4460

  • Spotlight

    Available for: OS X Yosemite v10.10

    Impact: Unnecessary information is included as part of the initial connection between Spotlight or Safari and the Spotlight Suggestions servers

    Description: The initial connection made by Spotlight or Safari to the Spotlight Suggestions servers included a user's approximate location before a user entered a query. This issue was addressed by removing this information from the initial connection and only sending the user's approximate location as part of queries.

    CVE-ID

    CVE-2014-4453 : Ashkan Soltani

  • System Profiler About This Mac

    Available for: OS X Yosemite v10.10

    Impact: Unnecessary information is included as part of a connection to Apple to determine the system model

    Description: The request made by About This Mac to determine the model of the system and direct users to the correct help resources included unnecessary cookies. This issue was addressed by removing cookies from the connection.

    CVE-ID

    CVE-2014-4458 : Landon Fuller of Plausible Labs

  • WebKit

    Available for: OS X Yosemite v10.10

    Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

    Description: A use after free issue existed in the handling of page objects. This issue was addressed through improved memory management.

    CVE-ID

    CVE-2014-4459

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsement. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date: