Summary:
Apple has released critical security updates for iPadOS, macOS, and the Safari web browser, addressing two actively exploited vulnerabilities in the WebKit web browser engine. The identified flaws are CVE-2023-42916, an out-of-bounds read issue that could leak sensitive information, and CVE-2023-42917, a memory corruption bug that might lead to arbitrary code execution. Apple is aware of these flaws being exploited in the wild on versions of iOS prior to 16.7.1, released on October 10, 2023.[/subscribe_to_unlock_form]
Summary:
Apple has released critical security updates for iPadOS, macOS, and the Safari web browser, addressing two actively exploited vulnerabilities in the WebKit web browser engine. The identified flaws are CVE-2023-42916, an out-of-bounds read issue that could leak sensitive information, and CVE-2023-42917, a memory corruption bug that might lead to arbitrary code execution. Apple is aware of these flaws being exploited in the wild on versions of iOS prior to 16.7.1, released on October 10, 2023.[emaillocker id="1283"]
Apple did not provide detailed information about ongoing exploitation, historical cases of disclosed zero-days have been linked to the delivery of spyware targeting high-profile individuals like activists, dissidents, journalists, and politicians. Notably, every third-party web browser available for iOS and iPadOS, including Google Chrome, Mozilla Firefox, and Microsoft Edge, relies on the WebKit rendering engine, making it a significant and broad attack surface
Recommendations:
References:
The following reports contain further technical details:
https://thehackernews.com/2023/12/zero-day-alert-apple-rolls-out-ios.html
[/emaillocker]