Breaking
December 12, 2024

Apple Just Patched These 20 Security Vulnerabilities With iOS 18.2 Jake Peterson | usagoldmines.com

When Apple dropped iOS 18.2 today, the headlines were mostly focused on big changes, including new Apple Intelligence features like Image Playground and Genmoji. But the quiet side of any Apple software release surrounds its security patches. iOS 18.2 is no exception: The company dropped 20 fixes for security flaws affecting iPhone running iOS 18.1.1 and older. And while none of them appear to be actively exploited at this time, they underscore the importance of updating your device as soon as possible.

Apple fixed issues with call muting, Lock Screen privacy, and malicious processing

When I scrolled through the list of fixes, a few jumped out to me in particular. First is the fix for an Audio flaw in which muting a call while its ringing might mean the mute function fails. It goes without saying that you should be able to trust the mute button when on a call, so any issue that might result in that mute button failing is concerning. Luckily, Apple says it fixed an “inconsistent user interface” to address the issue. Another concerning flaw affects VoiceOver: Via a flaw in this screen reader function, an attacker would be able to read your notifications on your Lock Screen, when normally these alerts would be hidden until your iPhone was unlocked.

There are also a number of fixes that prevent malicious apps, images, files, and web content from wreaking havoc on your device. An AppleMobileFileIntegrity flaw, for example, allows a malicious app to access your private information, while a SceneKit flaw allows a malicious file to lead to a denial of service, which could lock an authorized user out of the device.

The good news is it appears no one has been in active danger of being attacked with any of these flaws: Apple did not disclose that any have been actively exploited, which suggests malicious users either don’t know about the flaws, or don’t know how to take advantage of them. That said, now that these flaws are exposed, it’s only a matter of time before bad actors figure out how to exploit them, so updating your iPhone as soon as possible is still the smart move.

You can see the full list of flaws below:

  1. AppleMobileFileIntegrity (CVE-2024-54526): A malicious app may be able to access private information. The issue was addressed with improved checks.

  2. AppleMobileFileIntegrity (CVE-2024-54527): An app may be able to access sensitive user data. This issue was addressed with improved checks.

  3. Audio (CVE-2024-54503): Muting a call while ringing may not result in mute being enabled. An inconsistent user interface issue was addressed with improved state management.

  4. Crash Reporter (CVE-2024-54513): An app may be able to access sensitive user data. A permissions issue was addressed with additional restrictions.

  5. FontParser (CVE-2024-54486): Processing a maliciously crafted font may result in the disclosure of process memory. The issue was addressed with improved checks.

  6. ImageIO (CVE-2024-54500): Processing a maliciously crafted image may result in disclosure of process memory. The issue was addressed with improved checks.

  7. Kernel (CVE-2024-54494): An attacker may be able to create a read-only memory mapping that can be written to. A race condition was addressed with additional validation.

  8. Kernel (CVE-2024-54510): An app may be able to leak sensitive kernel state. A race condition was addressed with improved locking.

  9. Kernel (CVE-2024-44245): An app may be able to cause unexpected system termination or corrupt kernel memory. The issue was addressed with improved memory handling.

  10. libexpat (CVE-2024-45490): A remote attacker may cause an unexpected app termination or arbitrary code execution. This is a vulnerability in open source code and Apple Software is among the affected projects.

  11. libxpc (CVE-2024-54514): An app may be able to break out of its sandbox. The issue was addressed with improved checks.

  12. libxpc (CVE-2024-44225): An app may be able to gain elevated privileges. A logic issue was addressed with improved checks.

  13. Passwords (CVE-2024-54492): An attacker in a privileged network position may be able to alter network traffic. This issue was addressed by using HTTPS when sending information over the network.

  14. Safari (CVE-2024-44246): On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website. The issue was addressed with improved routing of Safari-originated requests.

  15. SceneKit (CVE-2024-54501): Processing a maliciously crafted file may lead to a denial of service. The issue was addressed with improved checks.

  16. VoiceOver (CVE-2024-54485): An attacker with physical access to an iOS device may be able to view notification content from the lock screen. The issue was addressed by adding additional logic.

  17. WebKit (CVE-2024-54479/CVE-2024-54502): Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved checks.

  18. WebKit (CVE-2024-54508): Processing maliciously crafted web content may lead to an unexpected process crash. The issue was addressed with improved memory handling.

  19. WebKit (CVE-2024-54505): Processing maliciously crafted web content may lead to memory corruption. A type confusion issue was addressed with improved memory handling.

  20. WebKit (CVE-2024-54534): Processing maliciously crafted web content may lead to memory corruption. The issue was addressed with improved memory handling.

Apple also released security updates for iPadOS, macOS Sequoia, macOS Sonoma, macOS Ventura, watchOS, tvOS, and visionOS. If you have any of these devices, you should update them as soon as possible as well.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Sending files from iPhone to Windows just got a lot faster and easier | usagoldmines.com
How GPU hardware acceleration works with Linux | usagoldmines.com
Get this Dell laptop with Core i5 for the super-budget price of $300 | usagoldmines.com
Samsung’s 34-inch 1440p ultrawide monitor drops 42% to its best price ever | usagoldmines.com
Android XR is Official as Google’s Extended Reality Platform, Samsung Shows Off First Headset Kellen...
How to Browse the Dark Web David Nield | usagoldmines.com
What People Are Getting Wrong This Week: CEO Shooter Conspiracy Theories Stephen Johnson | usagoldmi...
AirPods Pro 2 Hearing Aid and Hearing Test Features Approved to Launch in Canada Joe Rossignol | usa...
Apple Watch Ultra 2 Drops to $719.00 Low Price on Amazon With Christmas Delivery Mitchel Broussard |...
Apple Expands iPhone Driver's License Feature to 10th Location Joe Rossignol | usagoldmines.com
Four key steps to creating a DEX Operations Centre | usagoldmines.com
Apple fixes Passwords app security bug with new 18.2 update chiara.castro@futurenet.com (Chiara Cast...
Gemini 2.0 is here, as Google continues push towards agentic AI | usagoldmines.com
Google and Samsung reveal Project Moohan mixed-reality headset and Android XR, 'the first platform b...
Hollow Knight Silksong - everything we know | usagoldmines.com
Dune Awakening - everything we know so far | usagoldmines.com
Phantom Blade Zero - everything we know so far | usagoldmines.com
Apple TV Plus scores the streaming rights to All of You, a sci-fi romance from the co-creator of Shr...
Assassin's Creed Shadows' new combat overview details how skills, offensive attacks, and weapons are...
In an odd bit of propaganda, Belarus claims to have its own Starlink technology Eric Berger | usagol...
YouTube TV is hiking prices again after denying “erroneous” report days ago Kevin Purdy | usagoldmin...
Weight loss drugs may also treat addiction, Alzheimer’s, and heart disease Ian Johnston and Michael ...
Intel Arc B580 review: The first worthy budget GPU of the decade | usagoldmines.com
Adobe Acrobat Pro review: Still the gold standard | usagoldmines.com
The Windows 11 24H2 update is no longer blocked on these PCs | usagoldmines.com
YouTube TV Raises Price Yet Again, This Time to $82.99 in January Kellen | usagoldmines.com
You Should Plan Your 2025 Travel During These 'Dead Weeks' Emily Long | usagoldmines.com
You Can Get the Sonos Ace Wireless Headphones for Their Lowest Price Ever Right Now Pradershika Shar...
BMW’s iconic M3 is going electric – and I hope battery packs and e-motors don't destroy what makes i...
Assassin's Creed Infinity - everything we know so far | usagoldmines.com
Want to remove information about yourself online? You're not alone | usagoldmines.com
From gut feeling to data-driven strategy: AI’s role in holiday retail success | usagoldmines.com
This devious new malware technique looks to hijack Windows itself to avoid detection | usagoldmines...
Independent auditors confirm Mullvad VPN as secure chiara.castro@futurenet.com (Chiara Castro) | usa...
What is phishing and how dangerous is it? | usagoldmines.com
Garmin's 2024 data revealed – find out how good your stress and sleep scores are now stephen.warwick...
Intel Arc B580 review: The first worthy budget GPU of the decade | usagoldmines.com
Pokemon TCG Pocket Gets First Expansion Called “Mythical Island” on December 17 Kellen | usagoldmine...
Why a Chest Strap Is the Best Way to Track Your Heart Rate During Exercise Beth Skwarecki | usagoldm...
iOS 18 Updates Continue to Cause Delays in Apple's iOS 19 Plans Tim Hardwick | usagoldmines.com
Sony reveals that the transition of players from PS4 to PS5 is 'trending well' but doesn't see a 'ma...
I can’t keep track of all the Yellowstone spin-offs on Paramount Plus and yet another is reportedly ...
You've got more time – the great Google Maps Timeline switch gets a new deadline date | usagoldmine...
Krispy Kreme orders across the US disrupted after cyberattack | usagoldmines.com
Apple might have ditched plans for an M4 Extreme chip in favor of AI - and I think that's for the be...
Whoops! Apple seemingly just leaked its M4 MacBook Airs thanks to the macOS 15.2 update matthew.hans...
Microsoft announces that Xbox Insiders with Game Pass Ultimate can now stream select games on consol...
Samsung Galaxy S25 Ultra predicted colors: every rumored shade | usagoldmines.com
Thousands of Bitcoin ATM users may have personal data leaked after breach | usagoldmines.com
Mike Flanagan has written a Clayface movie and I can't wait to see his take on an underrated Batman ...
NASA’s boss-to-be proclaims we’re about to enter an “age of experimentation” Stephen Clark | usagold...
Major iPhone 17 Pro Redesign Backed by Supply Chain Info, Claims Leaker Tim Hardwick | usagoldmines....
Rising to the TOPS: How will NPUs and Windows AI grow in 2025? | usagoldmines.com
I’m a Windows guy. This little-known feature makes Macs more tolerable | usagoldmines.com
iOS 18.2 Mail Sorting Features Strangely Absent on iPad and Mac Tim Hardwick | usagoldmines.com
Thanks to Natural Language Search, your HomePod can now play you songs about cats | usagoldmines.co...
Workers are being punished for ignoring AI advice – even when they know better | usagoldmines.com
Final's new flagship headphones are incredible, and incredibly expensive | usagoldmines.com
Bad news, Blu-ray fans: LG just discontinued its entire range of 4K Blu-ray players and I’m really w...
Back where it started: “Do Not Track” removed from Firefox after 13 years Kevin Purdy | usagoldmines...
Leak seems to reveal that Epic Games Store will offer 16 free games for the holidays dash.wood@futur...
Sony confirms its intention to acquire FromSoftware parent company Kadokawa, but one analyst says th...
The Astro Bot Winter Wonder update is coming this week, adding a new Christmas-themed level and more...
The iPhone 17 could inherit the Pixel 9’s most distinctive design feature | usagoldmines.com
Microsoft will still let Windows 11 users send a fax, should they ever want that | usagoldmines.com
Got a Windows 11 gaming handheld like the Asus ROG Ally? You’re going to appreciate the changes Micr...
Data management and quality are falling short when it comes to what's needed for AI adoption | usag...
Microsoft finally delivers AirDrop-style file sharing between iPhones and PCs – here's how it works ...
Your Google Docs work may be about to be more beautiful than ever before | usagoldmines.com
IT decision makers are blindly trusting suppliers and wasting tech, research shows | usagoldmines.c...
iOS 18.2: Take a Hearing Test With AirPods Pro 2 Tim Hardwick | usagoldmines.com
OpenAI shows us how Apple Intelligence works with ChatGPT, which then promptly crashes erichs211@gma...
Europol announces takedown of major DDoS-for-hire network benedict.collins@futurenet.com (Benedict C...
Creature Commandos episode 3 proves James Gunn won't be afraid to kill his DCU darlings – the Max sh...
Best laptops 2024: Premium, budget, gaming, 2-in-1s, and more | usagoldmines.com
This high speed flash drive with USB-C and USB-A connections could make cloud storage obsolete | us...
Google says its next data centers will be built alongside wind and solar farms | usagoldmines.com
Dodge keeps true to its roots with the first electric Charger muscle car Jonathan M. Gitlin | usagol...
No, you can't run Windows on its tiny screen; minuscule mini PC has built-in display, fingerprint re...
The Best Free Way to Get Around a Paywall to Read an Article (and a Few More Methods to Try) Pranay ...
For the First Time, You’ll Be Able to Stream the Oscars Elizabeth Yuko | usagoldmines.com
Three Great Deals on iPads That Will Arrive Before Christmas Daniel Oropeza | usagoldmines.com
Seven Custom Lists I Use on My Hearth Display (and How to Make Them) Jordan Calhoun | usagoldmines.c...
Quordle today – my hints and answers for Thursday, December 12 (game #1053) | usagoldmines.com
NYT Strands today — my hints, answers and spangram for Thursday, December 12 (game #284) | usagoldm...
NYT Connections today — my hints and answers for Thursday, December 12 (game #550) | usagoldmines.c...
ChatGPT and Sora are down – here’s what you need to know about OpenAI's outage jacob.krol@futurenet....
Best PC computer holiday deals: Top picks from desktops to all-in-ones | usagoldmines.com
This Is The Ultimate Mouse Customization Tool for Mac Justin Pot | usagoldmines.com
The Best Stretches for a Stiff Lower Back Beth Skwarecki | usagoldmines.com
Apple Shares Ad Highlighting Genmoji in iOS 18.2 Juli Clover | usagoldmines.com
Everything You Need to Know About Apple Intelligence Juli Clover | usagoldmines.com
The Refurbished Steam Deck OLED Is a Stupid Good Deal Michelle Ehrhardt | usagoldmines.com
iOS 18.2 Features: Everything New in iOS 18.2 Juli Clover | usagoldmines.com
AMD VM security tools can be bypassed, letting hackers infilitrate your devices, experts warn | usa...
Russia takes unusual route to hack Starlink-connected devices in Ukraine Dan Goodin | usagoldmines.c...
Google Adds Two Features to Android to Fight Unwanted Bluetooth Tracking Kellen | usagoldmines.com
Six Services You Can Hire to Make Moving Day Less Horrible Jeff Somers | usagoldmines.com
'Chaat' Is the Cookbook to Warm Your Winter Bones Allie Chanthorn Reinmann | usagoldmines.com
The US energy sector is being put at risk by critical third-party vulnerabilities udinmwenefosa@gmai...

Leave a Reply