HomeSecurityApple: Fixes new zero-day bug that is actively used!

Apple: Fixes new zero-day bug that is actively being used!

Apple released some security updates to fix a zero-day vulnerability that hackers are actively exploiting to infiltrate iPhones and Macs running older versions of iOS and macOS.

Apple zero-day

The zero-day that was fixed today (referred to as CVE-2021-30869) was found in the XNU operating system kernel and was reported by Erye Hernandez and Clément Lecigne of the Google Threat Analysis Group and Ian Beer of Google Project Zero.

See also: VMware: Critical bug in default vCenter Server installs

Successful exploitation of this flaw leads to arbitrary code with kernel privileges on compromised devices.

“Apple knows of a report that this issue may have been actively used”, said Apple describing the zero-day flaw.

The full list of affected devices includes:

  • iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3 and iPod touch (6th generation) with iOS 12.5.5
  • and Mac with security update 2021-006 Catalina.

Apple also performed backporting in security updates for two zero-day vulnerabilities that had previously been patched, one of which was reported by The Citizen Lab and was used for the development of NSO Pegasus spyware on compromised devices.

See also: Microsoft Exchange Autodiscover: Bugs leak Windows credentials

In addition to today's zero-day flaw, Apple had to deal with an endless stream of zero-day bugs that are used in attacks targeting iOS and macOS devices:

  • two zero-day vulnerabilities earlier this month, one of them was also used to install the Pegasus spyware on iPhone,
  • the FORCEDENTRY exploit that was disclosed in August,
  • three iOS zero-days (CVE-2021-1870, CVE-2021-1871, CVE-2021-1872) in February, which were actively used,
  • an iOS zero-day (CVE-2021-1879) in March that may also have been actively used,
  • an iOS zero-day (CVE-2021-30661) and one in macOS (CVE-2021-30657) in April, exploited by the Shlayer malware,
  • three more iOS zero-days (CVE-2021-30663, CVE-2021-30665 and CVE-2021-30666) in May, bugs that allow arbitrary remote code execution (RCE) simply by visiting malicious websites,
  • a macOS zero-day(CVE-2021-30713) in May,
  • two zero-day iOS bugs (CVE-2021-30761 and CVE-2021-30762) in June that “may have been actively used” to hack older iPhone, iPad, and iPod devices.

See also: iOS 15 bug: Sound doesn't work on Instagram Stories

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS