HomeSecurityCISA to federal agencies: Update iPhones/Macs by February 25

CISA in federal agencies: Update iPhones/Macs by February 25th

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new flaw to its list of vulnerabilities being exploited by hackers. The new flaw is an Apple WebKit remote code execution bug that is used to target iPhones, iPads, and Macs.

Macs cisa

See also: CISA: Adds 8 vulnerabilities to the list of bugs used in attacks

According to the binding operational directive (BOD 22-01) issued by CISA in November, federal agencies must patch their systems against this vulnerability that affects iOS, iPadOS, and macOS devices.

CISA said that all Federal Civilian Executive Branch (FCEB) agencies must patch the vulnerability, listed as CVE-2022-22620, by February 25, 2022.

Yesterday, CISA also asked FCEB services to patch 15 other vulnerabilities tagged as being actively exploited, with CVE-2021-36934 — a Microsoft Windows SAM (Security Accounts Manager) flaw that allows privilege escalation and credential theft — having a February 24th deadline for patching.

See also: CISA to admins: Patch the highest severity SAP vulnerability

This is the third zero-day that Apple has fixed this year

CVE-2022-22620 is the third zero-day that Apple has patched since early 2022 and is a WebKit Use After Free issue that can be exploited to cause operating system errors and code execution on vulnerable devices.

Successful exploitation allows attackers to execute arbitrary code on iPhones, iPads, and Macs after opening maliciously crafted web pages using Safari.

Apple has addressed the vulnerability with improved memory management in iOS 15.3.1, iPadOS 15.3.1, and macOS Monterey 12.2.1.

The full list of affected devices is quite extensive and includes iPhone 6s and later, many iPad models, and Macs running macOS Monterey.

iPhones cisa

See also: CISA warns of critical vulnerabilities in Airspan Networks Mimosa

Although this flaw was likely only used in a small number of targeted attacks, it is still recommended to install the updates as soon as possible to block potential attack attempts, just as CISA urged earlier today.

In January, Apple patched two more zero-days that could allow attackers to monitor users' browsing activity and identities in real time (CVE-2022-22594) and gain arbitrary code execution with kernel privileges (CVE-2022-22587).

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS