Security News > 2023 > June > Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!

Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!
2023-06-22 21:36

Right at the start of June 2023, well-known Russian cybersecurity outfit Kaspersky reported on a previously unknown strain of iPhone malware.

Typically, iPhone malware that can compromise an entire device not only violates Apple's strictures about software downloads being restricted to the "Walled garden" of Apple's own App Store, but also bypasses Apple's much vaunted app separation, which is supposed to limit the reach of each app to a "Walled garden" of its own, containing only the data collected by that app itself.

That's because the kernel is responsible for all the "Walled gardening" protection applied to the device.

Therefore pwning the kernel generally means that attackers get to sidestep many or most of the security controls on the device altogether, resulting in the broadest and most dangerous sort of compromise.

Intriguingly, although Apple states no more than that the kernel zero-day "May have been exploited on iOS before version 15.7".

Every updated system, including watchOS and all three supported flavours of macOS, has been patched against this very kernel hole.


News URL

https://nakedsecurity.sophos.com/2023/06/22/apple-patch-fixes-zero-day-kernel-hole-reported-by-kaspersky-update-now/

Related vendor