BREAKING APPLE TECH REPORT: iOS 17.1.2 and macOS Sonoma 14.1.2 patch 2 actively exploited vulnerabilities

By

Published on

in

@acenewsservices

AceBreakingNews – Apple released an important security update today for iPhone, iPad, and Mac. The list of fixes is short, but iOS 17.1.2 and macOS Sonoma 14.1.2patch two web-based security flaws that have been actively exploited

@acenewsservices

Ace Press News From Cutting Room Floor: Published: Dec.01: 2023: 9 to 5MAC News by Michael Potuck: TELEGRAM Ace Daily News Link https://t.me/+PuI36tlDsM7GpOJe

apple zero-day exploit spyware security iOS
@acenewsservices

In the on-device release notes for these updates, Apple uses its typical boilerplate statement: “This update provides important security fixes and is recommended for all users.”

But Apple’s security updates page lists the details of the two exploited flaws – both of which were for WebKit and reported as actively exploited.

The first flaw used web processing to “disclose sensitive information,” and the second used web processing to allow for arbitrary code execution.

Here are the full details:

WebKit

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Description: An out-of-bounds read was addressed with improved input validation.

WebKit Bugzilla: 265041
CVE-2023-42916: Clément Lecigne of Google’s Threat Analysis Group

WebKit

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Description: A memory corruption vulnerability was addressed with improved locking.

WebKit Bugzilla: 265067
CVE-2023-42917: Clément Lecigne of Google’s Threat Analysis Group

@acenewsservices

Editor says …Sterling Publishing & Media Service Agency is not responsible for the content of external site or from any reports, posts or links and thanks for following as always appreciate every like, reblog or retweet and comment thank you

@acenewsservices
@acenewsservices

Hey!

Hey there, fellow Robloxian! Whether you’re here to discover hidden gem games, level up your building skills, or just stay in the loop with the latest events, you’re in the right place. This blog is all about sharing the coolest things in the Roblox universe—from developer tips to epic game reviews. So grab your Bloxy Cola, hit that follow button, and let’s explore the world of Roblox together! 🚀


Join the Club

Stay updated with our latest tips and other news by joining our newsletter.

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading