Malware & Threats

Apple Ships iOS 17.3, Warns of WebKit Zero-Day Exploitation

Apple pushes out fresh versions of its iOS and macOS platforms to fix WebKit vulnerabilities being exploited as zero-day in the wild.

Apple patches vulnerabilities

Apple is pushing out fresh versions of its flagship iOS and macOS platforms with patches for multiple WebKit vulnerabilities being exploited as zero-day in the wild.

The device maker said the newest iOS 17.3 and macOS Sonoma 14.3 updates fix at least 16 documented vulnerabilities that expose Apple users to code execution, denial-of-service and data exposure attacks.

The Cupertino company called urgent attention to a trio of WebKit security defects that have already been exploited in zero-day attacks.

As is customary, Apple did not release technical details or indicators of compromise to help defenders hunt for signs of compromise.  According to a barebones iOS 17.3 advisory, one of the WebKit flaws —  CVE-2024-23222 — may have been exploited against newer versions of the operating system. 

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited,” the company said. “A type confusion issue was addressed with improved checks.”

A separate advisory documents a pair of WebKit bugs — CVE-2023-42916 and CVE-2023-42917 — that Apple says may have been exploited against versions of iOS before iOS 16.7.1.

The iOS and MacOS updates also fix security problems in the Apple Neural Engine, CoreCrypto, Mail Search, Reset Services, Shortcuts and Time Zone.

Related: Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days

Advertisement. Scroll to continue reading.

Related: Microsoft: Russian Gov Hackers Stole Email Data From Senior Execs

Related: CISA Issues Emergency Directive on Ivanti Zero-Days

Related: Chinese Spies Exploited VMware Server Vulnerability Since 2021

Related Content

Nation-State

MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities.

Malware & Threats

More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.

Malware & Threats

Palo Alto Networks has started releasing hotfixes for the firewall zero-day CVE-2024-3400, which some have linked to North Korea’s Lazarus. 

Malware & Threats

Microsoft patches CVE-2024-29988 and CVE-2024-26234, two zero-day vulnerabilities exploited by threat actors to deliver malware.

Government

Ivanti releases a carefully scripted YouTube video and an open letter from chief executive Jeff Abbott vowing to fix the entire security organization.

Malware & Threats

Google ships a security-themed Chrome browser refresh to fix flaws exploited at the CanSecWest Pwn2Own hacking contest.

Malware & Threats

Despite a surge in zero-day attacks, data shows that security investments into OS and software exploit mitigations are forcing attackers to find new attack...

Mobile & Wireless

Apple rolls out urgent patches to fix multiple security flaws in its flagship iOS platform and warned about zero-day exploits in the wild.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version