• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
apple releases updates to address zero day flaws in ios, ipados,

Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari

You are here: Home / General Cyber Security News / Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari
April 8, 2023

Apple on Friday launched security updates for iOS, iPadOS, macOS, and Safari web browser to deal with a pair of zero-day flaws that are currently being exploited in the wild.

The two vulnerabilities are as follows –

  • CVE-2023-28205 – A use following free of charge issue in WebKit that could lead to arbitrary code execution when processing specially crafted web material.
  • CVE-2023-28206 – An out-of-bounds generate issue in IOSurfaceAccelerator that could enable an application to execute arbitrary code with kernel privileges.

Apple claimed it resolved CVE-2023-28205 with enhanced memory administration and the 2nd with greater input validation, introducing it is informed the bugs “might have been actively exploited.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Credited with identifying and reporting the flaws are Clément Lecigne of Google’s Menace Analysis Group (TAG) and Donncha Ó Cearbhaill of Amnesty International’s Security Lab.

Facts about the two vulnerabilities have been withheld in light-weight of active exploitation and to avert far more risk actors from abusing them.

The updates are offered in variation iOS 16.4.1, iPadOS 16.4.1, macOS Ventura 13.3.1, and Safari 16.4.1. The fixes also span a wide variety of equipment –

  • iPhone 8 and afterwards, iPad Pro (all styles), iPad Air 3rd generation and later, iPad 5th generation and later on, and iPad mini 5th generation and later on
  • Macs running macOS Huge Sur, Monterey, and Ventura

Apple has patched 3 zero-times given that the start off of the year. In February, Apple addressed yet another actively exploited zero-day (CVE-2023-23529) in WebKit that could final result in arbitrary code execution.

The improvement also will come as Google TAG disclosed that professional spyware sellers are leveraging zero-days in Android and iOS to infect cellular equipment with surveillance malware.

Observed this post appealing? Stick to us on Twitter  and LinkedIn to go through a lot more exceptional material we put up.


Some elements of this write-up are sourced from:
thehackernews.com

Previous Post: «researchers discover critical remote code execution flaw in vm2 sandbox Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library
Next Post: Iran-Based Hackers Caught Carrying Out Destructive Attacks Under Ransomware Guise iran based hackers caught carrying out destructive attacks under ransomware guise»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Microsoft Uncovers Banking AitM Phishing and BEC Attacks Targeting Financial Giants
  • University of Manchester Suffers Suspected Data Breach During Cyber Incident
  • Asylum Ambuscade: A Cybercrime Group with Espionage Ambitions
  • Barracuda Urges Swift Replacement of Vulnerable ESG Appliances
  • Google Launches Framework to Secure Generative AI
  • 5 Reasons Why Access Management is the Key to Securing the Modern Workplace
  • Security Experts Highlight Exploit for Patched Windows Flaw
  • Minecraft Users Warned of Malware Targeting Modpacks
  • Organizations Urged to Address Critical Vulnerabilities Found in First Half of 2023
  • Stealth Soldier: A New Custom Backdoor Targets North Africa with Espionage Attacks

Copyright © TheCyberSecurity.News, All Rights Reserved.