Close Menu
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
Facebook X (Twitter) Instagram
Trending
  • Jennifer Lopez and Ben Affleck reveal summer plans after Europe trip
  • T20 World Cup: Quiet contributions from Akshar Patel, Kuldeep Yadav and Ravindra Jadeja justify Rohit Sharma’s spin vision | Cricket News
  • The impact of a sedentary lifestyle on health
  • Bartok: The World of Lilette
  • Economists say the sharp rise in the U.S. budget deficit will put a strain on Americans’ incomes
  • Our Times: Williams memorial unveiled on July 4th | Lifestyle
  • Heatwaves in Europe are becoming more dangerous: what it means for travelers
  • Christian Science speaker to visit Chatauqua Institute Sunday | News, Sports, Jobs
Facebook X (Twitter) Instagram
The Daily PostingThe Daily Posting
  • Home
  • Android
  • Business
  • IPhone
    • Lifestyle
  • Politics
  • Europe
  • Science
    • Top Post
  • USA
  • World
The Daily PostingThe Daily Posting
IPhone

Apple’s security bug opens iPhones and iPads to RCE

thedailyposting.comBy thedailyposting.comMarch 26, 2024No Comments

[ad_1]

Apple has finally released details about the mysterious update it secretly pushed to iOS and iPadOS 17.4.1 last week.

At the end of the day, this update addresses issues such as: New vulnerability It is built into their respective operating systems and could allow a remote attacker to execute arbitrary code on an affected iPhone or iPad.

Apple iOS and iPadOS products affected by the vulnerable library include iPhone XS and later, iPad Pro 12.9 inch 2nd generation and later, iPad Pro 11 inch 1st generation and later, iPad Air 3rd generation and later, iPad mini 5th generation and later. It is included. . Users of these devices can reduce their risk from the vulnerabilities identified as follows: CVE-2024-1580 By installing new iOS and iPadOS updates.

Apple write out of bounds issue

CVE-2024-1580 is due to an out-of-bounds write issue in dav1d AV1, an open source library for decoding AV1 video on a wide range of devices and platforms. The two components of Apple iOS and iPadOS affected by this vulnerability are the Core Media framework for processing multimedia data on various Apple platforms and the Core Media framework for supporting live audio and video feed streams in mobile apps. This is his WebRTC implementation for the company.

In addition to the iOS and iPadOS updates, Apple also released updates this week to address CVE-2024-1580 in other products. Safari web browserMac OS sonoma and Ventura And that Vision OS Software for the company’s new Vision Pro headset. Apple’s update comes just weeks after the company released its iOS 17.4

Apple has confirmed that researchers from Google’s Project Zero bug-hunting team discovered the vulnerability and reported it to the company.

Potentially dangerous defect?

Security researcher Paul Ducklin said Apple’s Reluctant to reveal details of last week’s flaws This indicates that the company has likely deemed the defect to be dangerous.

“Apple’s deliberate silence when the first fix was published last week suggests that documenting the CVE-2024-1580 bug before patches are available for other platforms, especially macOS, is dangerous. My guess is that it was considered.” he wrote in a blog post.

We also believe that even the basic information about CVE-2024-1580 that the company published on March 26th provides enough information for attackers and researchers to reverse engineer the update and develop a working exploit. Ducklin said that suggests there is. He advised users and organizations with affected devices to immediately update to the latest versions of iOS, iPadOS, macOS, and other affected software.

Google rates this bug as a medium-severity issue with high attack complexity, meaning that an attacker would only need low-level privileges to exploit the bug, but would need access to the local network to be successful. or the need to be physically close to vulnerable systems.

Apple’s 3 zero-day bugs…so far.

So far in 2024, three of the four zero-day bugs Google has included in its Project Zero spreadsheet are Apple-related. The three bugs include: CVE-2024-23222a remote code execution bug in Safari’s WebKit browser engine, and CVE-2024-23225 and CVE-2024-23296two kernel vulnerabilities in iOS were actively exploited by attackers in attacks against iPhone users before Apple fixed them.

Google did not immediately respond to Dark Reading’s request for more information about the exploitability of the flaw or whether Project Zero researchers had actually observed any exploit activity targeting the flaw.

The fourth zero-day listed by Google in its 2024 Project Zero spreadsheet is: CVE-2024-0519This is a memory corruption bug that was actively being attacked in Chrome, which the company patched just days before Apple released a zero-day for WebKit Safari.



[ad_2]

Source link

thedailyposting.com
  • Website

Related Posts

Shocking moment a thief climbs over a counter in an east London store, struggles with a female shop assistant and steals an iPhone worth £700

June 28, 2024

AAA games for iPhone and iPad are not very popular with users

June 28, 2024

Apple’s price cuts boost iPhone sales in China

June 28, 2024
Leave A Reply Cancel Reply

ads
© 2025 thedailyposting. Designed by thedailyposting.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • Terms of Service
  • Advertise with Us
  • 1711155001.38
  • xtw183871351
  • 1711198661.96
  • xtw18387e4df
  • 1711246166.83
  • xtw1838741a9
  • 1711297158.04
  • xtw183870dc6
  • 1711365188.39
  • xtw183879911
  • 1711458621.62
  • xtw183874e29
  • 1711522190.64
  • xtw18387be76
  • 1711635077.58
  • xtw183874e27
  • 1711714028.74
  • xtw1838754ad
  • 1711793634.63
  • xtw183873b1e
  • 1711873287.71
  • xtw18387a946
  • 1711952126.28
  • xtw183873d99
  • 1712132776.67
  • xtw183875fe9
  • 1712201530.51
  • xtw1838743c5
  • 1712261945.28
  • xtw1838783be
  • 1712334324.07
  • xtw183873bb0
  • 1712401644.34
  • xtw183875eec
  • 1712468158.74
  • xtw18387760f
  • 1712534919.1
  • xtw183876b5c
  • 1712590059.33
  • xtw18387aa85
  • 1712647858.45
  • xtw18387da62
  • 1712898798.94
  • xtw1838737c0
  • 1712953686.67
  • xtw1838795b7
  • 1713008581.31
  • xtw18387ae6a
  • 1713063246.27
  • xtw183879b3c
  • 1713116334.31
  • xtw183872b3a
  • 1713169981.74
  • xtw18387bf0d
  • 1713224008.61
  • xtw183873807
  • 1713277771.7
  • xtw183872845
  • 1713329335.4
  • xtw183874890
  • 1716105960.56
  • xtw183870dd9
  • 1716140543.34
  • xtw18387691b

Type above and press Enter to search. Press Esc to cancel.