Jump to content
  • Apple fixes new zero-day used in attacks against iPhones, iPads

    alf9872000

    • 388 views
    • 2 minutes
     Share


    • 388 views
    • 2 minutes

    In security updates released on Monday, Apple has fixed the ninth zero-day vulnerability used in attacks against iPhones since the start of the year. 

     

    Apple revealed in an advisory today that it's aware of reports saying the security flaw "may have been actively exploited."

     

    The bug (CVE-2022-42827) is an out-of-bounds write issue reported to Apple by an anonymous researcher and caused by software writing data outside the boundaries of the current memory buffer.

     

    This can result in data corruption, application crashes, or code execution because of undefined or unexpected results (also known as memory corruption) resulting from subsequent data written to the buffer.

     

    As Apple explains, if successfully exploited in attacks, this zero-day could have been used by potential attackers to execute arbitrary code with kernel privileges.

     

    The complete list of impacted devices includes iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

     

    Apple addressed the zero-day vulnerability in iOS 16.1 and iPadOS 16 with improved bounds checking.

    Patch your iPhones and iPads

    While Apple has disclosed that it knows of active exploitation reports of this vulnerability in the wild, it has yet to release any information regarding these attacks.

     

    This will likely allow Apple customers to patch their devices before more attackers develop additional exploits and start using them in attacks targeting vulnerable iPhones and iPads.

     

    Even though this zero-day bug was most likely only used in highly-targeted attacks, installing today's security updates is strongly recommended to block any attack attempts.

     

    This is the ninth zero-day fixed by Apple since the start of the year:

     

    Source


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...