Apple on Tuesday, January 26 (January 27, Manila time), released security updates for the iOS and iPad OS platforms to resolve issues related to zero-day vulnerabilities exploited in the wild.
Apple advised users to install iOS 14.4 and iPad OS 14.4 as soon as possible, as it was aware of a report the issues “may have been actively exploited.”
According to an Apple support post explaining the security patch, an anonymous researcher was responsible for reporting the 3 zero-day vulnerabilities to Apple.
The first zero-day vulnerability, called CVE-2021-1782, affects the iOS kernel. Apple said of the vulnerability, “A malicious application may be able to elevate privileges.”
Meanwhile, CVE-2021-1870 and CVE-2021-1871 relate to vulnerabilities in the WebKit browser engine, wherein “a remote attacker may be able to cause arbitrary code execution.”
For more information on the feature and feature bug fixes included in the updates, Apple’s also listed them down here for users. – Rappler.com
There are no comments yet. Add your comment to start the conversation.