Latest OS X Update Contained iTunes Bug

If you're a Mac user and you downloaded this week's Mac OS X update (Mavericks 10.9.3), you may have noticed that your computer's Users/ and Users/Shared/ folders have disappeared. It turns out the disappearance is due to a security flaw in iTunes 11.2, which was part of the OS X Mavericks 10.9.3 update. 

The flaw is only really serious on iMacs and MacBooks with multiple user accounts, as it lets one account compromise the other accounts on the same computer. Apple has already patched the flaw with iTunes 11.2.1, which users can download via the Software Updater or from the Apple website.

MORE: 7 Ways to Lock Down Your Online Privacy

Apple explained in a support note that the bug had to do with how the computer handles the permissions of separate users on the same machine: "Upon each reboot, the permissions for the /Users and /Users/Shared directories would be set to world-writable, allowing modification of these directories [by any user]."

The issue also occurred on some Mavericks computers that had iTunes 11.2 installed separately without upgrading to Mavericks 10.9.3.

"This vulnerability was patched quickly, but the truth is that proper quality control should have meant that it was never introduced in the first place," wrote security expert Graham Cluley on his blog.

OS X Mavericks 10.9.3, which contained the buggy iTunes 11.2, also included an update to Safari 7.0.3, improved support for 4K screens, the ability to sync contacts and calendars between a mobile device and a Mac via USB, and a number of security updates that had been previously released.

Email jscharr@techmedianetwork.com or follow her @JillScharr and Google+.  Follow us@TomsGuide, on Facebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
nyc spring day AI image
OpenAI just unveiled new ChatGPT image generator powered by Sora — here's what you can do now
WWDC logo on yellow background
Apple WWDC 2025 date set for June 9 — iOS 19, Apple Intelligence and more expected
Motorola Razr Plus 2024 cover display
Motorola Razr Plus (2025) leaked specs hint at bigger upgrades — here's what we know
(L-R) Yura Borisov as Igor, Mark Eydelshteyn as Vanya, Karren Karagulian as Toros and Mikey Madison as Anora "Ani" Mikheeva in "Anora"
Hulu top 10 movies — here's what you need to stream right now
Nintendo Switch 2
Nintendo Switch 2 — industry insider just tipped release month and launch plans
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
  • jimmysmitty
    But I thought only Windows had security flaws????

    Sorry but I love it when this stuff comes out. It just goes to show that all software is the same no matter if it is Windows, OSX or Linux. All have flaws and holes, it just needs to be popular enough to be seen.
    Reply
  • house70
    iTunes: the most bloated useless buggy piece of software that will never ever touch any of my systems.
    Reply
  • nukemaster
    It only seems to be bloated and poorly designed on Windows.

    90% sure this is designed to make it look better on Mac OS.

    Kind of like Nvidia using obsolete instruction sets for PhysX when it runs on cpus.

    Marketing all the way.
    Reply
  • dstarr3
    I got so tired of dealing with iTunes on my PC that I completely removed it and made a virtual PC specifically for using iTunes, so that it doesn't get its filthy tendrils all tangled up in my real system.
    Reply
  • JD88
    People actually use iTunes?
    Reply
  • house70
    It only seems to be bloated and poorly designed on Windows. ...
    .

    How does this make it better? More than 90% of users are on Windows.
    Reply
  • infernocy
    Firstly winamp , a free software is way better that an official program by a "company" , and second isnt OSX a bug itself ?
    Reply
  • Darkk
    This is what happens when you deal with DRM infested software. Open source all the way.
    Reply
  • back_by_demand
    Nukemaster, did you read the bit where this was a bug in OSX? Not Windows? Are you high? GTFO TROLL!
    Reply