Site navigation

Apple Security Vulnerabilities: Is Your Device at Risk?

Michael Behr

,

Apple security vulnerabilities
If you’re using a newer generation of Apple device, you may need to update your security to ensure hackers can’t take control.

Apple has revealed and patched security vulnerabilities affecting its iPhone, iPad, and Mac products.

The tech giant warned that the zero-day flaws mean that threat actors could potentially take control of a victim’s device.

“An application may be able to execute arbitrary code with kernel privileges,” the company warned.

It also noted that the flaw was present in WebKit, the company’s browser engine that powers Safari and apps used on mobile devices.

“Processing maliciously crafted web content may lead to arbitrary code execution,” the company noted.

As such, these two flaws mean that a hacker could inject and run malicious code into a device without the owner’s permission and potentially take it over. For WebKit, this means that hackers could potentially use websites to hijack a device.

In addition, Apple said that it “is aware of a report that this issue may have been actively exploited”. However, it didn’t mention how many people were, or had potentially been, affected by the flaw.

Apple has released three new security updates for affected devices – macOS Monterey 12.5.1, and iOS 15.6.1 and iPadOS 15.6.1

The affected models include iPhone models later than the 6S, newer generation iPads (including all models of the iPad Pro), models from the iPad Air 2 onwards, iPad 5th generation and later, and the iPad mini 4.

In addition, the flaws affect Macs running the macOS Monterey operating system and 7th generation iPod Touches.

After releasing these three updates, Apple also released the Safari 15.6.1, which patches devices running macOS Big Sur and macOS Catalina. This protects against the security flaw that allows hackers to use malicious web content to execute code.


Recommended


Apple has said that users of devices running the affected software should protect themselves against the security vulnerabilities and ensure that their security is up to date by downloading the patches.

Since being released in June 2021, there have been 14 security updates for iOS 15. Nine of these have been needed to fix a similar code execution bug to the latest one. And five have come with the warning that Apple is aware that the flaw may have been exploited.

Commenting on the vulnerabilities, Security Consultant at Adarma Cian Heasley said: “Apple’s announcement of the need to update the operating system software for iPhone, Mac and iPad to fix two serious zero-day vulnerabilities highlights the importance for users to ensure that all their devices are updated with the latest software.

“By the time a vulnerability is public knowledge, attackers are often already actively exploiting it and once it become widely publicised other threat actors will scramble to take advantage of those who are slow to update their device’s operating system.

“Keeping devices secure is an ongoing process. To make the process easier, people can enable their device to perform automatic updates so that vulnerabilities are patched as soon as a fix is released.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

 

Michael Behr

Senior Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data