Apple patches exploited iOS, iPadOS zero-day

By
Follow google news

watchOS also affected and requires update.

Apple has issued an urgent out-of-band security update for its iOS and iPadOS mobile operating system, after a zero-day vulnerability that is under active exploitation was found.

Apple patches exploited iOS, iPadOS zero-day

The vulnerability in the WebKit browser engine can lead to universal site cross-scripting, Apple said.

Cross-scripting allows attackers to inject their own scripts via maliciously crafted web page content.

While Apple said it is aware that the vulnerability is being exploited, the company did not provide any further details on the attacks.

Users with iPhone 6s and later devices, all models of iPad Pro, iPad Air 2 and later, iPad 5th generation and mini 4, and 7th generation iPod touch should update to iOS 14.4.2 and iPadOS 14.4.2.

The vulnerability appears to affect watchOS as well, with Apple updating the operating system to 7.3.3 to patch the flaw.

Apple credited Google Threat Analysis Group researchers Clement Lecigné and Billy Leonard for finding the bug.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Supply chain attack hits 100 million-download Axios npm package

Supply chain attack hits 100 million-download Axios npm package

NAB is co-designing a SIEM with Databricks

NAB is co-designing a SIEM with Databricks

APRA pulls data submission system after security pentest

APRA pulls data submission system after security pentest

Councils push for federal shared security centre funding

Councils push for federal shared security centre funding

Log In

  |  Forgot your password?