HomeSecurityApple: Patches 2 zero-day vulnerabilities in iPhones and Macs

Apple: Patches 2 zero-day vulnerabilities in iPhones and Macs

Apple has released security updates to fix two zero-day vulnerabilities that hackers exploit on iPhone, iPad or Mac.

Zero-day vulnerabilities are security flaws that are known to attackers or researchers before the software vendor realizes or can fix them. In many cases, zero-days have public proof-of-concept exploits or are actively being exploited in attacks.

Today, Apple released macOS Monterey 12.5.1 and iOS 15.6.1/iPadOS 15.6.1 to resolve two zero-day vulnerabilities reported to have been used in an attack.

The two vulnerabilities are the same for all three operating systems, with the first being tracked as CVE-2022-32894. This vulnerability is an out-of-bounds write vulnerability in the operating system kernel.

The kernel is a program that acts as the core component of an operating system and has the highest permissions in macOS, iPadOS, and iOS.

Apple: Patches 2 zero-day vulnerabilities in iPhones and Macs
Apple: Patches 2 zero-day vulnerabilities in iPhones and Macs

See also: Microsoft patches Windows DogWalk zero-day

An application could use this vulnerability to execute code with kernel privileges. As this is the highest level of privilege, a process could execute any command on the device, effectively taking full control of it.

The second zero-day vulnerability is CVE-2022-32893 and is an out-of-bounds write vulnerability in WebKit, the web browser engine used by Safari and other applications that can access the web.

Apple says this flaw would allow an attacker to execute arbitrary code , and since it's in the browser, they could likely hack remotely by visiting a maliciously crafted website.

The bugs were reported by anonymous researchers and were fixed by Apple in iOS 15.6.1, iPadOS 15.6.1, and macOS Monterey 12.5.1 with improved checking for both bugs.

See also: Microsoft: Windows, Adobe zero-day exploits for Subzero development

The list of devices affected by both vulnerabilities is:

  • Macs running macOS Monterey
  • iPhone 6s and later
  • iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
Apple: Patches 2 zero-day vulnerabilities in iPhones and Macs
Apple: Patches 2 zero-day vulnerabilities in iPhones and Macs

Apple disclosed the active exploit, however, it did not release additional information about these attacks.

Most likely, these zero-day vulnerabilities were only used in targeted attacks, but it is still recommended to install today's security updates as soon as possible.

In March, Apple is patching two more zero-day bugs used in the Intel graphics driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675) that could also be used to execute code with kernel privileges.

In January, Apple fixed two more active zero-day bugs that allowed attackers to achieve arbitrary code execution with kernel privileges (CVE-2022-22587) and monitor web browsing activity and user identities in real time (CVE-2022-22594).

In February, Apple released security updates to fix a new zero-day flaw that was being used to hack iPhones, iPads , and Macs, leading to operating system crashes and remote code execution on compromised devices after processing maliciously crafted web content.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS