iTnews

Apple patches exploited zero-days in iOS and iPadOS

By Juha Saarinen, iTnews on Nov 6, 2020 12:55PM
Apple patches exploited zero-days in iOS and iPadOS

Targeted exploitation, but not election related.

Users are advised to apply Apple's recent iOS and iPadOS 14.2 security update as soon as possible, as it fixes three chained vulnerabilties that the company said are being exploited in the wild.

The three vulnerabilities were discovered by Google's Project Zero researchers who reported them to Apple and are also handled in Apple's iOS 12.4.9 update.

One memory corruption bug allows attackers to use a maliciously crafted font to cause run arbitrary code on users' devices.

An exploited memory initialisation issue that allows malicious applications to read operating system kernel memory was also found by Project Zero.

The security researchers also found a type confusion problem in iOS and iPadOS that allows malicious applications to run arbitrary code with kernel privileges.

Google's Threat Analysis Group director Shane Huntley said the zero-day vulnerabilities were deployed against specific targets.

Targeted exploitation in the wild similar to the other recently reported 0days. Not related to any election targeting.

— Shane Huntley (@ShaneHuntley) November 5, 2020

A Google bug hunting tool, the Open Source Software Fuzz (OSS-Fuzz) found remote code execution vulnerabilities in the libxml2 library, which are patched in iOS and iPadOS 14.2.

In total, the 14.2 update handles 24 security issues, and also brings 100 new emojis.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apple google ios ipados security

Partner Content

MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
Partner Content MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
MSI launches innovative new laptops
Partner Content MSI launches innovative new laptops
Improving returns from SD-WAN spending
Sponsored Content Improving returns from SD-WAN spending
NCS expands into Australia in partnership with Optus Enterprise
Sponsored Content NCS expands into Australia in partnership with Optus Enterprise

Sponsored Whitepapers

The risky business of open source
The risky business of open source
Mitigating open source risk in your organisation
Mitigating open source risk in your organisation
How to choose a WAF that's right for you
How to choose a WAF that's right for you
The global telco 5G cloud gaming opportunity
The global telco 5G cloud gaming opportunity
Building a ransomware remediation backup strategy
Building a ransomware remediation backup strategy

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
By Juha Saarinen, iTnews
Nov 6 2020
12:55PM
0 Comments

Related Articles

  • Unc0ver jailbreak opens up Apple iOS 11 to 13.5
  • Apple loses court case against security vendor Corellium
  • Apple, GroupM, others ask for tough protection for data in Google lawsuit
  • ACCC to examine competition between Apple and Google app stores
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra pilots its first neurodiversity recruitment program

Telstra pilots its first neurodiversity recruitment program

Update Chrome or risk remote takeover, US govt warns

Update Chrome or risk remote takeover, US govt warns

Accellion hack behind Reserve Bank of NZ data breach

Accellion hack behind Reserve Bank of NZ data breach

Google unravels state-of-art Android and Windows exploit chains

Google unravels state-of-art Android and Windows exploit chains

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.