Зарегистрируйтесь сейчас для лучшей персонализированной цитаты!

Get updating: Apple releases iOS 15.3.1 patch for 'actively exploited' security flaw

11 февраля 2022 г Hi-network.com

If you haven't already upgraded to iOS 15.3, now might be a good time to do it because of a security flaw Apple has now patched.

Apple released iOS 15.3 earlier this month, but it didn't include one fix for a security flaw it has now addressed in iOS 15.3.1. 

Apple

  • Unlock the best new features in iPhone 15, iOS 17, and Apple Watch with these tips
  • iOS 17: The most impactful new iPhone features are also the ones you'll notice the least
  • New iPhone 15 models compared: iPhone 15 vs. Plus vs. Pro vs. Pro Max
  • One subtle (but important) reason to buy the iPhone 15 Pro instead of the iPhone 14 Pro

Details from Apple, as usual, are scant but it gave enough information to suggest it is a serious bug because it can lead to malicious code execution simply by users opening a web page in the Apple Safari browser. 

SEE: 5G: Where we are, where we're going next

"Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited," Apple said.   

The update is available for iPhone 6s and later, iPad Pro, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch 7th generation.

Since the bug affects WebKit, the browser engine for Safari, it also affects macOS. Apple also released macOS Monterey 12.2.1 to address the issue on Macs.  

The bug, like many security flaws, was a memory flaw that code written in C++ is particularly prone to. 

According to Microsoft and Google, about 70% of a security issues are caused by memory safety problems and those issues are tied to flaws written in C and C++, arguably the most important family of programming languages that have been used for decades in multi-million line infrastructure systems like Windows, WebKit, Chrome, Android, Firefox, the Linux kernel, and now embedded systems for Internet of Things devices.

Security

8 habits of highly secure remote workersHow to find and remove spyware from your phoneThe best VPN services: How do the top 5 compare?How to find out if you are involved in a data breach -- and what to do next
  • 8 habits of highly secure remote workers
  • How to find and remove spyware from your phone
  • The best VPN services: How do the top 5 compare?
  • How to find out if you are involved in a data breach -- and what to do next

tag-icon Горячие метки: Технологии и оборудование Безопасность и охрана

Copyright © 2014-2024 Hi-Network.com | HAILIAN TECHNOLOGY CO., LIMITED | All Rights Reserved.