• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
apple releases security updates to patch critical ios and macos

Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws

You are here: Home / General Cyber Security News / Apple Releases Security Updates to Patch Critical iOS and macOS Security Flaws
December 12, 2023

Apple on Monday introduced security patches for iOS, iPadOS, macOS, tvOS, watchOS, and Safari web browser to deal with several security flaws, in addition to backporting fixes for two lately disclosed zero-days to more mature gadgets.

This involves updates for 12 security vulnerabilities in iOS and iPadOS spanning AVEVideoEncoder, ExtensionKit, Discover My, ImageIO, Kernel, Safari Private Browsing, and WebKit. macOS Sonoma 14.2, for its component, resolves 39 shortcomings, counting 6 bugs impacting the ncurses library.

Notable between the flaws is CVE-2023-45866, a critical security issue that could make it possible for an attacker in a privileged network posture to inject keystrokes by spoofing a keyboard.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The vulnerability was disclosed by SkySafe security researcher Marc Newlin final 7 days. It has been remediated in iOS 17.2, iPadOS 17.2, and macOS Sonoma 14.2 with enhanced checks, the iPhone maker claimed.

Approaching WEBINAR Cracking the Code: Discover How Cyber Attackers Exploit Human Psychology

At any time questioned why social engineering is so effective? Dive deep into the psychology of cyber attackers in our impending webinar.

Sign up for Now

Also released by Apple is Safari 17.2, containing fixes for two WebKit flaws – CVE-2023-42890 and CVE-2023-42883 – that could guide to arbitrary code execution and a denial-of-service (DoS) affliction. The update is offered for Macs jogging macOS Monterey and macOS Ventura.

iOS 17.2 and iPadOS 17.2, in addition to addressing a Siri bug that could allow an adversary with bodily entry to acquire delicate knowledge, packs in a security up grade in the kind of Contact Essential Verification, which makes certain privacy of iMessage discussions by enabling consumers to validate the contacts they are speaking with.

“iMessage Contact Important Verification advances the state of the artwork of Vital Transparency deployments by owning user devices on their own confirm regularity proofs and assure regularity of the KT method across all person devices for an account,” Apple noted in a technical explainer in Oct 2023.

“These advancements defend towards important listing compromise as well as compromise of the transparency service itself, and can detect split views presented by both companies.”

Cybersecurity

Coinciding with the updates, Apple has also released iOS 16.7.3 and iPadOS 16.7.3 to near out as several as 8 security issues, two of which relate to WebKit (CVE-2023-42916 and CVE-2023-42917) and were being disclosed by Redmond as possessing been actively exploited in the wild earlier this month.

Equally the vulnerabilities have been patched in tvOS 17.2 and watchOS 10.2 as well. No more particulars are offered as but concerning the nature of the exploitation and the danger actors that may perhaps be working with them.

Located this posting appealing? Adhere to us on Twitter  and LinkedIn to examine more exceptional material we post.


Some components of this short article are sourced from:
thehackernews.com

Previous Post: «new critical rce vulnerability discovered in apache struts 2 New Critical RCE Vulnerability Discovered in Apache Struts 2 – Patch Now
Next Post: New MrAnon Stealer Malware Targeting German Users via Booking-Themed Scam new mranon stealer malware targeting german users via booking themed scam»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.