Apple fixes its ninth major zero-day threat of 2022
Another day, another out-of-bounds write issue to worry Apple
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
Applehas released a fix for another new zero-day vulnerability being actively used in the wild - bringing the total number of addressed such flaws to nine this year.
The flaw, discovered in both Apple smartphone and tablet devices, is described as an out-of-bounds write issue that threat actors can leverage to run arbitrary code with kernel privileges on vulnerableendpoints, this vulnerability is now tracked as CVE-2022-42827.
It was reported to the Cupertino tech giant anonymously,Security Affairsreported, and was fixed through improved bounds checking for iOS 16.1 and iPadOS 16.
Nine zero-days this year alone
“Apple is aware of a report that this issue may have been actively exploited.” Apple’s security advisory reads.
Users with an iPhone 8 and newersmartphone, any iPad Pro model, iPad Air 3rd generation and newer, iPad 5th generation and newer, or iPad mini 5th generation and newer, should apply the latest updates immediately, as they are vulnerable to this zero-day.
This is the ninth zero-day vulnerability that Apple addressed this year, after fixing two in January (CVE-2022-22587 and CVE-2022-22594), one in February (CVE-2022-22620), two in March (CVE-2022-22674 and CVE-2022-22675), one in May (CVE-2022-22675), one in August (CVE-2022-32894), and one in September (CVE-2022-32917).
Apple Safari patched to fix potentially dangerous zero-day flaws>Apple releases another urgent iOS security patch, so install now>Here are the best antivirus programs right now
CVE-2022-32917, fixed last month, allows malicious apps to execute arbitrary code with kernel privileges, just as this latest zero-day. This one, too, was fixed with improved bounds checks.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
iOS 16, Apple’s latest version of itsoperating systemfor mobile phones, was released in mid-September this year. This release brought improvements to many apps, from a redesigned Home app for your smart appliances to better privacy features, and a big focus on the lock screen, with new fonts, colors, and themes to choose from. There’s also satellite calling coming to the newly-announced iPhone 14 models, a feature coming in November 2022.
iPadOS 16, the latest version of the operating system designed for tablets, was released yesterday.
Via:Security Affairs
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
Rising AI threats are making firms turn back to human intelligence
Thousands of employees could be falling victim to obvious phishing scams every month
Google’s new AI video maker for businesses is now available on Workspace