Apple has released an update to patch a series of vulnerabilities in iOS, macOS, Safari and many other platforms, update now!
Apple recently released a patch for a series of simple to serious vulnerabilities that have been confirmed on iOS and macOS platforms, Safari, watchOS, tvOS and iTunes. The most dangerous case is a flaw in WebKit that allows an attacker to gain access, hijack the device and execute code remotely.
More specifically, among all the vulnerabilities that have been tagged with the CVE identifier on Apple's service platforms, there are 30 cases affecting iOS, 11 cases affecting Safari and 27 vulnerabilities exist in macOS. For its part, Apple recommends that global users quickly update to iOS 13.4, Safari 13.1 and macOS Catalina 10.15.3 to limit the risks from the aforementioned vulnerabilities.
Apple is often very tight-lipped when it comes to details of vulnerabilities in security updates, but this time is the exception. Cupertino has outlined eight critical vulnerabilities that have just been patched in Apple's WebKit browser tool that could allow hackers to deploy a variety of malicious activities, from cross-site scripting (XSS) attacks. to remote code execution in iOS and Safari.
The most serious of these is a flaw in WebKit that has the identifier CVE-2020-3897. It is dangerous in that it can be abused to remotely execute code on the device, but also requires victim interaction. Specifically, a hacker must trick the victim into accessing a malicious website or opening a malicious file.
'This vulnerability allows remote attackers to execute arbitrary code on the affected settings of Safari, and exists in the object conversion buffer. By taking actions in JavaScript, an attacker can take advantage of this vulnerability to execute code in the context of the current process, 'said Dustin Childs, head of the Zero Day Initiative security team.
Update your Apple platforms / services to the latest version for your own safety.
You should read it
- Apple patched many zero-day bugs in iOS 15.4.1 and macOS 12.3.1 updates
- Apple Patches Zero-Day Vulnerability That Could Let iPhones, iPads, and MacBooks Get Hacked
- Apple releases iOS 14.4.2, iOS 12.5.2, and watchOS 7.3.3 updates that patch the critical zero-day vulnerability
- How to patch browser security holes
- Immediately patch CWP vulnerability that allows code execution as root on Linux servers
- iOS 11.1 was released with a series of new emoji and fixes for the KRACK vulnerability
- Apple releases iOS 15.3.1 to completely fix Safari security flaw
- Warning of dangerous Spring4Shell vulnerability, there are signs of scanning and exploiting
- Discovered a new zero-day vulnerability on macOS that allows attackers to run commands remotely
- Apple released iOS 11.3, macOS 10.13.4, tvOS 11.3 and watchOS 4.3
- Apple released OS X Lion update 10.7.3
- Microsoft updated Patch Tuesday in October 2020, patching the 'Ping of Death' vulnerability on Windows 10
Maybe you are interested
Detecting software vulnerabilities Samsung can be rewarded with 1 million USD
Serious security vulnerabilities in Safari and Chrome have existed for 18 years
GPT-4 exploits vulnerabilities faster and cheaper than humans
Warning of 16 security vulnerabilities causing Microsoft products to be attacked
16 new security vulnerabilities can cause systems using Microsoft software to be attacked
Microsoft fixes 149 security vulnerabilities on Windows, users should update immediately