Apple releases patches for major iOS and macOS security vulnerabilities | Tech Reader

Date:

Share:


Apple has released a fix for a zero-day vulnerability that bad actors could exploit to take full control of an iPhone, an iPad or a computer running macOS Monterey. The tech giant’s security advisory is pretty light on details, but it has identified CVE-2022-3289 as a vulnerability discovered by an anonymous researcher. It says the flaw could be exploited “to execute arbitrary code with kernel privileges,” which means attackers could act as the user and gain admin control of the target device. The company says it’s aware that the vulnerability may have already been exploited.

In addition, Apple has also rolled out a fix for a vulnerability affecting WebKit, the engine used by Safari, Mail and many other iOS and macOS apps. According to the company, it allows attackers to arbitrarily execute code and could hence be used to, among other things, download more malware. Like the first vulnerability, Apple credits an anonymous researcher for the discovery of this flaw — it also knows that it may have already been exploited and used to compromise iOS and Mac devices. 

Both flaws are present in macOS Monterey 12.5.1, and Apple has rolled out a patch for the operating system. They both affect the same set of iPhones and iPads, as well, particularly: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later and iPod touch (7th generation). Since both flaws are likely being actively exploited right now, it’s probably wise for owners of all the aforementioned devices to install the patches by downloading the latest software update.

All products recommended by Tech Reader are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.



Source link

━ more like this

The UK government reportedly wants Anthropic to expand its presence in London

While the US and Anthropic are in the midst of a major dispute, the UK is trying to sway the San Francisco-based AI...

Samsung will discontinue its Messages app in July and replace it with Google’s

Samsung is putting the final nail in the coffin for its own messaging app. The smartphone maker posted an "End of Service Announcement"...

Fitness tracking under scrutiny as Strava military data leak exposes personnel

Your Strava runs might feel private, but a new Strava military data leak shows how easily that information can reveal more than your...

This canceled LG Rollable phone makes today’s designs look dated

This canceled LG Rollable smartphone highlights how far behind today’s designs feel. A newly surfaced teardown from JerryRigEverything shows the device wasn’t just...

Leaks suggest Xbox Cloud Gaming could bring back lost classics

Xbox Cloud Gaming leaks are pointing to something players have wanted for years, a way to bring back older titles that quietly disappeared....
spot_img