Apple fixes new zero-day flaw being actively exploited by hackers


Apple has fixed fresh vulnerabilities in iOS and macOS, including a zero-day flaw being actively exploited by hackers.


The zero-day flaw, known as CVE-2022-32917, allows a malicious app to run arbitrary code on an affected device with kernel privileges, Apple said in a security update.


Apple fixed the bug in updates for iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6 and macOS Big Sur 11.7.


Apple warned that it is aware that this flaw “may have been actively exploited”.


According to TechCrunch, this is the eighth zero-day vulnerability fixed by Apple this year.


In addition to these fixes, Apple also released a fix for a Safari browser flaw that could lead to address bar spoofing.


The security fixes were released along with iOS 16, which brings several security and privacy features, including support for Apple Passkeys and Lockdown Mode.


“Keeping your software up to date is one of the most important things you can do to maintain your Apple product’s security,” said the company.


After a software update is installed for iOS, iPadOS, tvOS, and watchOS, it cannot be downgraded to the previous version.


Last month, Apple released new software updates for iPhones, iPads and Macs to fix two security vulnerabilities known by the tech giant to be actively exploited by attackers.


The two vulnerabilities were found in WebKit, the browser engine that powers Safari and other apps, and the kernel, essentially the operating system’s core.


The tech giant had said the WebKit bug could be exploited if a vulnerable device accessed or processed “maliciously crafted web content (that) may lead to arbitrary code execution”.


–IANS


na/dpb

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

Dear Reader,

Business Standard has always strived hard to provide up-to-date information and commentary on developments that are of interest to you and have wider political and economic implications for the country and the world. Your encouragement and constant feedback on how to improve our offering have only made our resolve and commitment to these ideals stronger. Even during these difficult times arising out of Covid-19, we continue to remain committed to keeping you informed and updated with credible news, authoritative views and incisive commentary on topical issues of relevance.

We, however, have a request.

As we battle the economic impact of the pandemic, we need your support even more, so that we can continue to offer you more quality content. Our subscription model has seen an encouraging response from many of you, who have subscribed to our online content. More subscription to our online content can only help us achieve the goals of offering you even better and more relevant content. We believe in free, fair and credible journalism. Your support through more subscriptions can help us practise the journalism to which we are committed.

Support quality journalism and subscribe to Business Standard.

Digital Editor


Originally appeared on: TheSpuzz

Scoophot
Logo