Security News > 2020 > November > Apple patches three actively exploited iOS zero-days

Apple patches three actively exploited iOS zero-days
2020-11-05 14:41

Apple has patched today three iOS zero-day vulnerabilities actively exploited in the wild and affecting iPhone, iPad, and iPod devices.

The zero-days were addressed by Apple earlier today, with the release of iOS 14.2, the mobile OS's latest stable version.

The third actively exploited bug is a kernel privilege escalation flaw caused by a type confusion issue that makes it possible for malicious applications to execute arbitrary code with kernel privileges.

Apple have fixed three issues reported by Project Zero that were being actively exploited in the wild.

The Project Zero researchers also disclosed an elevation of privileges zero-day in the Windows kernel exploited in the wild, affecting all versions between Windows 7 and Windows 10.


News URL

https://www.bleepingcomputer.com/news/security/apple-patches-three-actively-exploited-ios-zero-days/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110