HomeUpdatesApple fixes new zero-day vulnerability on iPhones and iPads

Apple fixes new zero-day vulnerability in iPhones and iPads

Apple has addressed a new zero-day vulnerability used to attack iPhones by releasing security updates.

Apple zero-day

A zero-day vulnerability is a vulnerability in software or hardware that the vendor is unaware of (until it is exploited or discovered by a researcher). These types of vulnerabilities are particularly dangerous because they can be exploited by attackers before the vendor has a chance to patch them. That's why they're called "zero-day" - because there are zero days between the time the vulnerability is discovered and the time it can be exploited.

See also: Windows zero-day: JavaScript files bypass MoTW

Apple said in a security advisory released yesterday that it is aware of reports that the zero-day bug "may have been exploited."

The CVE-2022-42827 is an out-of-bounds write caused by software writing data outside the boundaries of the current memory buffer. Apple was notified of the bug by an anonymous researcher.

Exploitation of the flaw may lead to data corruption, application crashes, or code execution.

See also: A zero-day in Windows Mark of the Web gets an unofficial update

According to Apple, successful exploitation of this zero-day vulnerability could allow potential attackers to execute code with kernel privileges.

The affected devices are: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation.

With the release of iOS 16.1 and iPadOS 16, Apple fixed this new zero-day vulnerability.

iPhone zero day

Update your iPhones and iPads to protect yourself

While Apple has confirmed that there are reports of people actively exploiting this vulnerability, it has not provided details about these attacks.

This way, Apple customers will be able to update their devices before attackers have a chance to create new ways to exploit the zero-day vulnerability to attack iPhones and iPads.

See also: 900 servers compromised using a zero-day Zimbra vulnerability

Current security updates are important to install, even though the zero-day flaw is likely only used in targeted attacks. By installing the update, you will be able to block any attack attempts.

Since the beginning of the year, Apple has fixed several zero-day bugs.

  • In September, Apple released a security update to address a flaw in the iOS Kernel (CVE-2022-32917).
  • In August, it fixed two more zero-days in the iOS Kernel (CVE-2022-32894) and WebKit (CVE-2022-32893).
  • In March, Apple patched two zero-days in the Intel Graphics Driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675).
  • In February, the company released security updates to fix a zero-day bug in WebKit that was used to attack iPhones, iPads, and Macs.
  • In January, Apple fixed two more zero-day bugs that allowed code execution with kernel privileges (CVE-2022-22587) and the monitoring of users' web browsing activity (CVE-2022-22594)

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS