HomeSecurityApple's emergency update fixes zero-day in Macs and Watches

Apple's emergency update fixes zero-day on Macs and Watches

An emergency update to address a zero-day vulnerability that can be exploited to carry out attacks targeting Mac and Apple Watchhas been released by Apple.

See also: iOS 15.5 released: All the new features Apple brings

Apple

For those who don't know, Zero-days are security flaws that the software vendor is not aware of and has not yet patched. In some cases, this type of vulnerability may also have publicly available PoCs before a patch arrives or may be actively exploited.

In security advisories issued on Monday, Apple revealed that it is aware of reports of this bug.

The flaw is an out-of-bounds write issue (CVE-2022-22675) in AppleAVD (a kernel extension for audio and video decoding) that allows applications to execute arbitrary code with kernel privileges.

The bug was reported by anonymous researchers and fixed by Apple in macOS Big Sur 11.6, watchOS 8.6 , and tvOS 15.5 with improved limit checking.

The list of affected devices includes Apple Watch Series 3 or later, Macs with macOS Big Sur, Apple TV 4K, Apple TV 4K (2nd generation) , and Apple TV HD.

See also: Final credits for the iPod: Apple retires the legendary music player

While Apple disclosed reports of active exploitation of the vulnerability, it did not release additional information about these attacks.

zero day

By hiding information, the company likely aims to allow security updates to reach as many Apple Watches and Macs as possible before attackers discover the zero-day and start deploying exploits for other attacks.

Although this zero-day was likely only used in targeted attacks, it is recommended that all users install the latest macOS and watchOS as soon as possible to block any attack attempts.

In March, two more actively exploitable zero-days were discovered in the Intel graphics driver (CVE-2022-22674) and the AppleAVD media decoder (CVE-2022-22675), the latter also now supported in older versions of macOS, watchOS 8.6, and tvOS 15.5.

See also: Kuo: Apple will bring USB-C port to iPhone, AirPods and other products

These zero-days affect iPhones (iPhone 6s and later), Macs running macOS Monterey, and many iPad.

Over the past year, the company has also patched a long list of zero-days that were being actively exploited to target iOS, iPadOS, and macOS devices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS