Skip to main content

Posts

Showing posts with the label April 08

Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari.

#Information_is_Power . Click on this link http://informationispowah.blogspot.com/2023/04/apple-releases-updates-to-address-zero.html to read details. #we_inform_the_uninformed . Apple on Friday released security updates for  iOS, iPadOS ,  macOS , and  Safari web browser  to address a pair of zero-day flaws that are being exploited in the wild. The two vulnerabilities are as follows – CVE-2023-28205  – A  use after free issue  in WebKit that could lead to arbitrary code execution when processing specially crafted web content. CVE-2023-28206  – An  out-of-bounds write issue  in IOSurfaceAccelerator that could enable an app to execute arbitrary code with kernel privileges. Apple said it addressed CVE-2023-28205 with improved memory management and the second with better input validation, adding it’s aware the bugs “may have been actively exploited.” Credited with discovering and reporting the flaws are Clément Lecigne of Google’s Threat Analysis Group (TAG) and Donncha Ó Cearbh