Apple has issued updates that patch 21 security holes in a wide range of software and services contained in the latest Mac operating system.
The worst of the flaws allow miscreants to remotely install malware on a machine with little or no action required by the user. Among them are vulnerabilities in Adobe Flash, which were disclosed and patched more than a month ago and are being actively exploited in the wild. Apple also patched its own software for handling documents based on PDF, or portable document format.
Other defects in BOM, (short for Bill of Materials), CoreGraphics, Libsystem, and other OS X components could also lead to the execution of malicious code. One vulnerability in Safari could allow attackers to steal cookies used to authenticate a user on a sensitive website while another allowed users to download potentially unsafe files without warning.