Apple patches zero
Full article510 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Other details about the vulnerability were thin.
Apple has released updates for its mobile, iPad and computer operating systems, fixing a zero-day flaw that appears to be the subject of active exploitation.
The patch comes mere days after another update that tackled 40 vulnerabilities. The latest software update comes in the wake of reports that the Israeli spyware firm NSO Group had developed a hacking tool that helps its customers remotely compromise iOS systems. Whether the patch address those technical issues was not immediately clear. Apple did not immediately respond to a request for comment.
The prior Apple update did not address the NSO Group exploits.
The iOS 14.7.1, iPadOS 14.7.1 and Big Sur 11.5.1 patch notes are likewise mum, other than to say that an anonymous researcher brought the vulnerability to Apple’s attention. The issue involved improper access to kernel mode, which a hacker could have abused to access the underlying hardware on a device, and manipulate some memory functions.
“An application may be able to execute arbitrary code with kernel privileges,” the notes for the updates issued Monday read. “Apple is aware of a report that this issue may have been actively exploited.”
Apple zero-day, or previously unrevealed, flaws are more common than they once were, to the point that last year zero-day broker Zerodium temporarily stopped acquiring them. By one count, this is the 13th zero-day issue Apple has patched in 2021.
A Microsoft researcher said Monday that he had previously been working on the bug to finish an exploit and was “surprised” to see it released as “in the wild,” or spreading among ordinary users.
‘The vulnerability is as trivial and straightforward as it can get,” Saar Amar wrote in an explanation of how it worked. He said he first found it four months ago.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-zero-day-nso-group-big-sur-ios/