HomeUpdatesApple fixes zero-day vulnerabilities in Mac systems

Apple fixes zero-day vulnerabilities in Mac systems

Apple has released emergency security updates to fix two zero-day vulnerabilities in Intel-based Mac systems. The vulnerabilities are already being used in attacks.

Apple zero-day

Generally, a vulnerability is called a zero-day when it has been publicly disclosed or used in attacks, without a security update available .

Apple said it is aware of a report that says the vulnerabilities have been exploited. One vulnerability was found in macOS Sequoia JavaScriptCore (CVE-2024-44308) and the second in WebKit (CVE-2024-44309).

See also: Palo Alto Networks patches two zero-day firewall vulnerabilities

The vulnerability in JavaScriptCore allows attackers to perform remote code execution via specially crafted web content. The WebKit vulnerability, on the other hand, allows cross-site scripting (CSS) attacks.

Apple says it fixed both zero-day vulnerabilities with macOS Sequoia 15.1.1. However, the components affected by the vulnerabilities are also in other Apple operating systems, so there are fixes in iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, and visionOS 2.1.1.

Both vulnerabilities were discovered by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group, but no further details have been published on how they were exploited.

See also: Botnet exploits zero-day vulnerability in GeoVision

It's worth noting that with the two new vulnerabilities, Apple has patched a total of six zero-days so far in 2024.This number is significantly lower than last year, where the company patched 20 zero-day bugs.

Apple fixes zero-day vulnerabilities in Mac systems

What are the latest techniques for dealing with Zero-Day vulnerabilities?

One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.

Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.

See also: NSO Group used another WhatsApp zero-day

Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS