Security News > 2021 > January > Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers

Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers
2021-01-26 20:45

Apple today released software updates to patch vulnerabilities in iPhones and iPads that may have been exploited by miscreants to silently snoop on victims from afar.

Apple said it is "Aware of a report that this issue may have been actively exploited." How would one inject malicious code into a device? Look no further than.... CVE-2021-1871, CVE-2021-1870: Also fixed in iOS 14.4 and iPadOS 14.4, a logic bug in WebKit that can be exploited by a malicious webpage - opened in, say, Safari - to execute arbitrary code.

Again, Apple is aware this may have been exploited in the wild.

The CVE-2021-1782 flaw is also fixed in tvOS 14.4, available for Apple TV 4K and Apple TV HD models, and watchOS 7.3, available for the Apple Watch Series 3 and later.

In addition to these fixes, Apple also emitted Xcode 12.4 that fixes CVE-2021-1800, a bug that can be exploited by malicious applications running on someone's Mac to access a user's personal files.

The iOS and iPadOS patches come a day after Google revealed North Korea's hackers had targeted information security researchers, luring them to a website that seemingly contained a Chrome zero-day exploit to infect their Windows PCs and offering them malware-infected Visual Studio project files.


News URL

https://go.theregister.com/feed/www.theregister.com/2021/01/26/apple_ios_zero_days/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-04-02 CVE-2021-1800 Unspecified vulnerability in Apple Xcode
A path handling issue was addressed with improved validation.
local
low complexity
apple
5.5
2021-04-02 CVE-2021-1870 A logic issue was addressed with improved restrictions.
network
low complexity
apple webkitgtk fedoraproject
critical
9.8
2021-04-02 CVE-2021-1871 A logic issue was addressed with improved restrictions.
network
low complexity
apple debian fedoraproject
critical
9.8
2021-04-02 CVE-2021-1782 Improper Locking vulnerability in Apple products
A race condition was addressed with improved locking.
local
high complexity
apple CWE-667
7.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110