2 min read

Patch your iPhones and Macs against "actively exploited" zero-day right now

Graham CLULEY

July 27, 2021

Ad One product to protect all your devices, without slowing them down.
Free 90-day trial
Patch your iPhones and Macs against "actively exploited" zero-day right now

If you're the owner of an iPhone, iPad, or Apple Mac you should update your system right now.

Apple has released a major security update for its devices, after finding a zero-day flaw that the company indicates has been the focus of in-the-wild attacks by hackers, and might have been used to plant malware.

As is its wont, Apple has not released any real details about the flaw, presumably in an attempt to reduce the chances of other parties exploiting the security vulnerability.

According to a security advisory published on Apple's website, the flaw - technically known as CVE-2021-30807 -  was reported to the firm by an anonymous researcher, and involves a memory corruption flaw
in the IOMobileFrameBuffer kernel extension used for managing the screen framebuffer, that can be abused to execute arbitrary code on a device with kernel privileges.

If a malicious hacker's code successfully gains kernel privileges it seizes God-like control over the device.

What makes things all the more serious is Apple's warning that the security flaw has been used in real-world attacks:

“Apple is aware of a report that this issue may have been actively exploited.”

Proof-of-concept code to exploit the flaw has been published on Twitter

Users are advised to update to the latest versions of iOS (14.7.1), iPadOS (14.7.1), and macOS (11.5.1) to protect against the issue.

Another security researcher, Saar Amar, claims to have also uncovered the vulnerability four months ago, although he had not yet reported it to Apple as he was still working on methods to exploit the flaw. Amar described the vulnerability as being "as trivial and straightforward as it can get."

With details of how to exploit the vulnerability published in the wild, and Apple's claims that it has been actively exploited, there really is no time to wait - everyone should update their Apple devices.

To update your Mac or MacBook, choose System Preferences from the Apple menu in the top-left of the screen. Then click Software Update to see if any updates are available and follow instructions.

If your iPhone or iPad has not yet installed the latest security update, open Settings, and choose General > Software Update and follow instructions.

tags


Author



Right now

Top posts

Abode IoT Security Camera Vulnerabilities Would Let Attackers Insert Images, Bitdefender Finds

Abode IoT Security Camera Vulnerabilities Would Let Attackers Insert Images, Bitdefender Finds

December 21, 2021

2 min read
Online Shoppers Beware, Mobile Scams Are on the Rise

Online Shoppers Beware, Mobile Scams Are on the Rise

December 17, 2021

2 min read
The Holiday Guide to Tech Support: Fixing the Family Computer

The Holiday Guide to Tech Support: Fixing the Family Computer

November 24, 2021

2 min read
Bitdefender Celebrates 20 Years of Cybersecurity Leadership

Bitdefender Celebrates 20 Years of Cybersecurity Leadership

November 04, 2021

3 min read
Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

Bitdefender Study Reveals How Consumers Like (and Dislike) Managing Passwords

October 26, 2021

3 min read
What are drive-by download attacks and how do you prevent them?

What are drive-by download attacks and how do you prevent them?

October 25, 2021

2 min read

FOLLOW US ON

SOCIAL MEDIA


You might also like

Unknown Person Zoom-Bombs Meeting in Italian Parliament and Blasts Anime Adult Content Unknown Person Zoom-Bombs Meeting in Italian Parliament and Blasts Anime Adult Content
Silviu STAHIE

January 21, 2022

1 min read
FBI Links Diavol Ransomware to Trickbot, Offers IOCs and Mitigations FBI Links Diavol Ransomware to Trickbot, Offers IOCs and Mitigations
Filip TRUȚĂ

January 21, 2022

2 min read
Data of 500,000 already vulnerable people stolen from Red Cross Data of 500,000 already vulnerable people stolen from Red Cross
Radu CRAHMALIUC

January 20, 2022

1 min read