Apple’s Emergency Updates Address Exploited iOS Zero-Day Vulnerabilities
Apple has issued emergency security updates in response to the exploitation of two zero-day vulnerabilities in iOS, prompting urgent action to safeguard iPhone users from potential cyber threats.
The vulnerabilities, identified in the iOS Kernel (CVE-2024-23225) and RTKit (CVE-2024-23296), granted attackers arbitrary kernel read and write capabilities, enabling them to bypass critical kernel memory protections.
In its advisory released on Tuesday, Apple acknowledged awareness of reported exploits targeting these vulnerabilities, prompting swift action to mitigate potential risks. The company swiftly addressed the security flaws in iOS 17.4, iPadOS 17.4, iOS 16.76, and iPad 16.7.6 through enhanced input validation mechanisms.
Extensive Impact
A wide array of Apple devices, including iPhone XS and later, iPad Pro models, and various iPad generations, are impacted by these vulnerabilities.
See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses
Ongoing Threats
While the origins of the disclosed zero-days remain undisclosed by Apple, such vulnerabilities are frequently exploited in state-sponsored surveillance operations targeting high-profile individuals like journalists and political dissidents.
Though no ongoing exploitation in the wild has been reported by Apple, the urgency of installing the security updates cannot be overstated, especially considering the potential risks associated with unpatched devices.
Trending: Offensive Security Tool: Upload_Bypass