Apple has recently released a patch to address an actively exploited zero-day vulnerability affecting older iPhone and iPad devices. The vulnerability had been present for several years and was being actively exploited by malicious entities for malicious purposes. The patch resolves the issue by patching the code, thus preventing malicious users from exploiting it and gaining access to a user's device.
The vulnerability, discovered by Google's Project Zero, affects all devices running iOS 12.4 or earlier. As such, any devices running iOS 13 or newer are not affected. It was discovered that malicious entities were actively exploiting the vulnerability by creating a malicious website which, if visited by the user, would install malicious code on the device, giving the attacker full access to the device.
Apple has released a security update to address the issue. For users that have already been affected, they are advised to reset their password and update their device to the latest version of iOS to ensure it's security.
Overall, this instance of a zero-day vulnerability affecting iOS devices serves as a reminder that users should always be aware and remain vigilant when using the internet, especially when using their devices. It also highlights Apple's response to ensuring the security of their products, quickly patching the issue after it was discovered.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 23 Jan 2023 19:41:02 +0000