HomeSecurityApple update: Fixes zero-day bugs affecting iPhone, Mac

Apple update: Fixes zero-day bugs affecting iPhone, Mac

Apple has released emergency security updates to fix two zero-day vulnerabilities that allow cybercriminals to compromise iPhones, iPads, and Macs .

The company said it has received reports that suggest the vulnerabilities are already being exploited by malicious users.

See also: Apple and Meta shared data with hackers pretending to be researchers

Apple zero-day

The first zero-day vulnerability in Apple products is an "out-of-bounds write issue" (CVE-2022-22674) found in the Intel Graphics Driver. The second vulnerability is an "out-of-bounds read issue" (CVE-2022-22675) in the AppleAVD media decoder that allows applications to execute code with kernel privileges.

Apple was notified of the zero-day bugs by anonymous researchers and fixed them with theiOS 15.4.1, iPadOS 15.4.1, and macOS Monterey 12.3.1.

According to the company, the devices affected by the two zero-day vulnerabilities are:

  • iPhone 6s and later models
  • iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
  • Macs running macOS Monterey

See also: Apple: Reader apps will sign up new subscribers without paying fees

While Apple said that the zero-day vulnerabilities are being used to compromise iPhones, iPads, and Macs, it did not provide further details about the attacks. The company, apparently, chose not to reveal all the information it has until the updates are installed on as many iPhones, iPads, and Macs as possible. This will prevent other threat actors from learning the details. It is believed that the zero-day vulnerabilities have only been used in targeted attacks, but Apple is urging its users to update their devices immediately to block potential attack attempts.

Apple update: Fixes zero-day bugs affecting iPhone, Mac

Apple: New zero-day vulnerabilities are constantly appearing

In January, Apple patched two more active zero-day bugs. One could allow attackers to execute code with kernel privileges (CVE-2022-22587). The second allowed users' online activity to be monitored and their identities tracked in real time (CVE-2022-22594).

Last month, Apple released updates for another zero-day bug. The vulnerability affected iPhones, iPads, and Macs, causing problems with the operating system and allowing remote code execution on compromised devices.

See also: Zero-day in Java Spring allows remote code execution

The company also addressed multiple zero-day vulnerabilities in iOS, iPadOS, and macOS throughout 2021.

Apple products (iPhone, iPad, Mac) are used by a large number of users and the company tries to promptly fix such security issues to keep its customers safe.

Apple update: Fixes zero-day bugs affecting iPhone, Mac

A few words about zero-day vulnerabilities

"Zero-day" is a broad term that describes newly discovered security issues that hackers to attack systems. Essentially, it is a vulnerability that has been discovered by attackers/researchers before the company has identified it. Since the vendors of the vulnerable products are not aware of the vulnerability, they do not have a patch, increasing the chances of an attack being successful. For this reason, companies rush to fix vulnerabilities as soon as they become known.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS