viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
Apple rushes out patches for two zero-days threatening iOS and macOS users
Technology

Apple rushes out patches for two zero-days threatening iOS and macOS users

01/04/2022

Apple rushes out patches for two zero-days threatening iOS and macOS users

Apple on Thursday released fixes for two critical zero-day vulnerabilities in iPhones, iPads, and Macs that give hackers dangerous access to the internals of the OSes the devices run on.

Apple credited an anonymous researcher with discovering both vulnerabilities. The first vulnerability, CVE-2022-22675, resides in macOS for Monterey and in iOS or iPadOS for most iPhone and iPad models. The flaw, which stems from an out-of-bounds write issue, gives hackers the ability to execute malicious code that runs with privileges of the kernel, the most security-sensitive region of the OS. CVE-2022-22674, meanwhile, also results from an out-of-bounds read issue that can lead to the disclosure of kernel memory.

Apple disclosed bare-bones details for the flaws here and here. “Apple is aware of a report that this issue may have been actively exploited,” the company wrote of both vulnerabilities.

Advertisement

Raining down Apple zero-days

CVE-2022-22674 and CVE-2022-22675 are the fourth and fifth zero-days Apple has patched this year. In January, the company rushed out patches for iOS, iPadOS, macOS Monterey, watchOS, tvOS, and HomePod Software to fix a zero-day memory corruption flaw that could give exploiters the ability to execute code with kernel privileges. The bug, tracked as CVE-2022-22587, resided in the IOMobileFrameBuffer. A separate vulnerability, CVE-2022-22594, made it possible for websites to track sensitive user information. The exploit code for that vulnerability was released publicly prior to the patch being issued.

Apple in February pushed out a fix for a use after free bug in the Webkit browser engine that gave attackers the ability to run malicious code on iPhones, iPads, and iTouches. Apple said that reports it received indicated the vulnerability—CVE-2022-22620—might also have been actively exploited.

A spreadsheet Google security researchers maintain to track zero-days shows Apple fixed a total of 12 such vulnerabilities in 2021. Among those was a flaw in iMessage that the Pegasus spyware framework was targeting using a zero-click exploit, meaning devices were infected merely by receiving a malicious message, without any user action required. Two zero-days that Apple patched in May made it possible for attackers to infect fully up-to-date devices.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Original Content podcast: ‘The Rise of Skywalker’ makes some questionable choices – TechCrunch
“Star Wars: The Rise of Skywalker” opened Friday to mediocre …

Original Content podcast: ‘The Rise of Skywalker’ makes some questionable choices – TechCrunch

Monero emerges as crypto of choice for cybercriminals
53 Studios | Getty Images For cybercriminals looking to launder …

Monero emerges as crypto of choice for cybercriminals

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Chrome 79 arrives with password warnings, real-time phishing protection, and WebXR Device API
    Chrome 79 arrives with password warnings, real-time …
    10/12/2019
  • China proposes global data security standards
    China proposes global data security standards
    08/09/2020
  • Plenty of Fish app leaked profile data set to private – TechCrunch
    Plenty of Fish app leaked profile data …
    24/12/2019
  • PlayStation 5 gets Godfall looter-slasher from Gearbox Publishing
    SpaceX and NASA break down what their …
    02/05/2020
  • Amazon delays New World MMO until spring 2021
    Amazon delays New World MMO until spring …
    11/07/2020

Popular Posts

  • Omnipotent BMCs from QCT remain vulnerable to critical Pantsdown threat
    Omnipotent BMCs from QCT remain vulnerable to …
    26/05/2022 0
  • 10 Times Going to the Toilet Went …
    27/04/2022 0
  • Microsoft accounts can go passwordless, making “password123” a thing of the past
    Businesses are adopting Windows 11 more quickly …
    27/04/2022 0
  • Russia wages “relentless and destructive” cyberattacks to bolster Ukraine invasion
    Russia wages “relentless and destructive” cyberattacks to …
    27/04/2022 0
  • 10 of the Most Random Reality Shows …
    28/04/2022 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2022 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh