Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Month of Apple Bugs Releases QuickTime Flaw

Add as a preferred source on Google

The Month of Apple Bugs project—a follow up to a Month of Kernel Bugs and A Month of Browser Bugs—vowed to release details of bugs and securty exploits in Apple’s Mac OS X operating system and popular Mac OS X applications…and the project is off and running, publicizing the details of a possible security exploit in Apple’s QuickTime software by overflowing buffers with specially crafted rtsp:// URLs. The bug impacts QuickTime 7.1.3 for both Mac OS X and Windows.

The Month of Bugs projects have been the center of some controversy; many software developers and security analysts feel it is irresponsible to publish the details of working security vulnerabilities in widely-available software, arguing that only feeds the ever-active malware communities lurking on the Internet’s dark underbelly and the possibility of real-world exploits. The responsible thing to do, they argue, is report the issues to the software vendors and security agencies, and publicize the details only when a patch or fix is available.

Recommended Videos

On the other hand, the “report and keep quiet” methodology rubs some people the wrong way: if their computers are vulnerable, they want to know the details now, regardless of whether a patch or fix is available, so at least they know what they’re up against. The participants in the Bug a Month projects—such as the “mysterious” programmer operating under the tag “LMH”—have also expressed frustration at the amount of time software developers like Apple and Microsoft take to patch seemingly trivial vulnerabilities.

In any case, it would appear that Apple’s Mac OS X and key applications—certainly not immune to security problems but thusfar spared the malware pain of the Windows world—are under a very public microscope.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
The maker of ChatGPT wants to make open-source projects less of a security bargain
OpenAI launches Patch the Planet for open-source security, with over 30 open-source projects on board.
openai-chatgpt-os

OpenAI has launched Patch the Planet, a new initiative aimed at fixing one of the internet's quietest problems – the chronically underfunded security of open-source software.

Patch the Planet pairs OpenAI's most security-capable AI models with Trail of Bits, a security firm that has committed its entire research organization to the effort, alongside support from HackerOne and Calif.

Read more
I sifted through the Prime Day chaos to find the best Apple deals actually worth buying
Apple's about to hike prices. Prime Day 2026 is your last chance to save up to $150 on MacBooks, AirPods, and iPads.
Prime Day Deals on Apple Products

Apple is set to increase the prices for its upcoming iPhones and MacBooks, as the company can no longer offset the rising RAM and storage costs. That means, if you are looking to upgrade your aging device, you should buy the current-generation Apple products rather than wait for the new ones.

And since Amazon Prime Day is offering good discounts on the latest iPhones, iPads, MacBooks, and other Apple accessories, this is the perfect time to buy them. Here are my favorite Amazon Prime Day deals for Apple products. 

Read more
This sneaky photo trick gets AI chatbots to ignore their safety rules
Florida International University researchers built a method that nearly doubled the rate of harmful responses from a tested AI model using nothing but pixel-level edits in an image.
JaiLIP AI chatbot exploit image

A photo that looks completely ordinary to you could carry a hidden instruction to trick an AI chatbot into ignoring its safety rules, according to new research out of Florida International University. The study found that pixel-level alterations in an image that are invisible to the human eye can be enough to confuse the model reading the image and lead it to generate responses it would normally block.

Hacking what the AI sees

Read more