Apple patches new zero-day bug used to hack iPhones and Macs – BleepingComputer

Apple has released security updates to fix a zero-day vulnerabilityexploited in the wild by attackers to hack into iPhones and Macs running older iOS and macOS versions.

The zero-day patched today (tracked as CVE-2021-30869) [1,2] was found in the XNU operating system kerneland was reported byErye Hernandez and Clment Lecigne of Google Threat Analysis Group, and Ian Beer of Google Project Zero.

Successful exploitation of this bugleads to arbitrary code execution with kernel privileges on compromised devices.

"Apple is aware of a report that this issue may have been actively exploited," Apple said when describing the zero-day bug.

The complete list of impacted devices includes:

Apple also backportedsecurity updates for two previously patchedzero-days, one of themreported by The Citizen Lab andused to deploy NSO Pegasus spyware on hacked devices.

Besides today's zero-day, Apple had to deal with what looks likean unending stream of zero-day bugs used in attacks targeting iOS and macOSdevices:

Update: A previous version of the story said Apple fixed threezero-days, one of themused to deploy spyware. We have updated the storyto correctly say the company patched a single zero-day exploited in the wild.

More:

Apple patches new zero-day bug used to hack iPhones and Macs - BleepingComputer

Related Posts

Comments are closed.