Apple patches three iOS zero‑days under attack

Apple patches three iOS zero‑days under attack

The company emits emergency updates to fix bugs affecting devices ranging from iPhones to Apple Watches



Apple has rolled out an update for its iOS and iPadOS operating systems to patch three zero-day security flaws that are being actively exploited in the wild. The trio of flaws affects various versions of iPhones and iPads and the latest generation of iPod touch.


“Apple is aware of a report that this issue may have been actively exploited,” reads Apple’s security advisory describing each security hole that is being plugged with the release of iOS and iPadOS 14.4.


The list of impacted devices includes iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and the 7th generation iPod touch. The Cupertino-based tech titan also issued security updates for one of the vulnerabilities across a range of its other offerings, including Apple Watch (watchOS 7.3) and Apple TVs (tvOS 14.4).


As usual, there’s no word about the perpetrators and targets of the zero-day attacks, which exploit loopholes in the operating system’s kernel and the WebKit browser engine


The first flaw, tracked as CVE-2021-1782 and located in the OS kernel, is a race condition bug that could lead to an escalation of privilege, which could be exploited by an attacker using a malicious application. In plain English this it means that an attacker could use the application to gain additional privileges in the device’s operating s ..

Support the originator by clicking the read the rest link below.