Site icon The Cybersecurity Daily News

Two Apple Zero Day Bugs Patched In iOS Update

Apple Zero Day

CyberDaily: Cybersecurity news-

In the latest developments, Apple has patched up another set of zero-day vulnerabilities in an iOS 12.5.4 update, that were being actively exploited in the wild. These Apple Zero Day vulnerabilities were detected and reported by anonymous security researchers.

Two zero-days vulnerabilities:

The two Apple zero-day vulnerabilities tracked as CVE-2021-30761 and CVE-2021-30762, are a result of memory corruption and use after free in the WebKit browser engine, respectively. Both of these vulnerabilities were detected and reported by anonymous security researchers.

WebKit is a browser engine developed by Apple and primarily used in its Safari web browser, as well as all iOS web browsers to provide HTML content.

“Apple is aware of a report that this issue may have been actively exploited,” states Apple when addressing the two iOS 12.5 Apple zero-day vulnerabilities.

Security experts are of the opinion that these two Apple zero-day bugs could be potentially exploited by using specially architectured web content that would prompt arbitrary code execution following the loading by targets on unpatched devices.

The devices that were affected due to the zero-days were the older iPhones (iPhone 5s, iPhone 6, iPhone 6 Plus), iPads (iPad Air, iPad mini 2, iPad mini 3), and the iPod touch (6th generation).

Also read,

2021- An Apple Zero-Day Saga

The year 2021 has witnessed Apple patched a range of zero-days, with a majority of them being reported as getting exploited in the wild.

A list of the Apple zero-days that have been addressed and patched up since the start of the year is as follows:

Exit mobile version