Skip to main content

Woburn, MA – April 10, 2015 -Kaspersky Lab security researchers have discovered a vulnerability in the kernel of Darwin – an open-source component of both the OS X and iOS operating systems. This “Darwin Nuke” vulnerability leaves OS X 10.10 and iOS 8 devices exposed to remotely-activated denial of service (DoS) attacks that can damage the user’s device and impact any corporate network to which it is connected. The experts call on consumers to update devices with the OS X 10.10.3 and iOS 8.3 software releases, which no longer include this vulnerability.

Analysis of the vulnerability by Kaspersky Lab revealed that the devices affected by the threat include those with 64-bit processors and iOS 8: iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad Air 2, iPad mini 2, and iPad mini 3.

The “Darwin Nuke” vulnerability is exploited while processing an IP packet of specific size and with invalid IP options. Remote attackers can initiate a DoS (denial of service) attack on a device with OS X 10.10 or iOS 8, sending an incorrect network packet to the target. After processing the invalid network packet, the system will crash. Kaspersky Lab’s researchers discovered that the system will crash only if the IP packet meets the following conditions:

   - The size of the IP header should be 60 bytes.

   - The size of the IP payload should be less than or equal to 65 bytes.

   - The IP options should be incorrect (invalid option size, class, etc.)

“At first sight, it is very hard to exploit this bug, as the conditions attackers need to meet are not trivial ones. But persistent cybercriminals can do so, breaking down devices or even affecting the activity of corporate networks. Routers and firewalls would usually drop incorrect packets with invalid option sizes, but we discovered several combinations of incorrect IP options that are able to pass through the Internet routers. We’d like to warn all OS X 10.10 and iOS 8 users to update devices to OS X 10.10.3 and iOS 8.3 releases,” says Anton Ivanov, senior malware analyst at Kaspersky Lab.

Kaspersky Lab’s products protect OS X against the “Darwin Nuke” vulnerability with the Network Attack Blocker feature. Starting with Kaspersky Internet Security for Mac 15.0, this threat is detected as DoS.OSX.Yosemite.ICMP.Error.exploit. For more information, visit Securelist.

Kaspersky Lab suggestion the following tips for boosting the security of Mac devices:

  1. Use a Web browser that has a solid track record of fixing security issues promptly.

  2. Run "Software Update" and patch the machine promptly when updates are available.

  3. Use a password manager to help cope with phishing attacks.

  4. Install a good security solution.

Tips to make your iPhone secure can be found at: http://blog.kaspersky.com/iphone-maximum-security-tips/

To learn more about Mac threats, read the latest post on Eugene Kaspersky's Official Blog.

About Kaspersky Lab
Kaspersky Lab is the world’s largest privately held vendor of endpoint protection solutions. The company is ranked among the world’s top four vendors of security solutions for endpoint users*. Throughout its more than 17-year history Kaspersky Lab has remained an innovator in IT security and provides effective digital security solutions for large enterprises, SMBs and consumers. Kaspersky Lab, with its holding company registered in the United Kingdom, currently operates in almost 200 countries and territories across the globe, providing protection for over 400 million users worldwide. Learn more at www.kaspersky.com.

For the latest in-depth information on security threat issues and trends, please visit:

Securelist | Information about Viruses, Hackers and Spam
Follow @Securelist on Twitter

Threatpost | The First Stop for Security News
Follow @Threatpost on Twitter

Media Contacts
Susan Rivera
781.503.5211
susan.rivera@kaspersky.com

* The company was rated fourth in the IDC rating Worldwide Endpoint Security Revenue by Vendor, 2013. The rating was published in the IDC report "Worldwide Endpoint Security 2014–2018 Forecast and 2013 Vendor Shares (IDC #250210, August 2014). The report ranked software vendors according to earnings from sales of endpoint security solutions in 2013.

Kaspersky Lab Finds “Darwin Nuke” Vulnerability in OS X and iOS

Kaspersky Lab Finds “Darwin Nuke” Vulnerability in OS X and iOS
Kaspersky Logo