Breaking
November 21, 2024

Apple patches 2 zero-day vulnerabilities used to attack Intel-based Macs Renato Bond | usagoldmines.com

Apple has released a critical update for macOS to patch a couple of zero-day vulnerabilities. The security patches are also available for iPhones and iPads.

Intel-based Macs targeted by security attacks

The macOS Sequoia 15.1.1 update includes 2 security fixes, both of which affect Safari. The vulnerabilities were discovered by two security experts who are part of Google’s Threat Analysis Group, Clément Lecigne and Benoît Sevens. They reported their findings to Apple, which confirmed that it is aware that the issues may have been actively exploited by hackers. Details about the attacks have not been revealed.

According to the Security Releases page on the company’s portal, the first of these patches are for an issue tracked under CVE-2024-44308, and is related to JavaScriptCore. A vulnerability allowed the processing of malicious web content, which could then lead to arbitrary code execution. The bug was addressed by improving checks.

The second vulnerability is tracked under CVE-2024-44309, and affects WebKit. This issue could allow malicious content on a web page to initiate a cross site scripting attack. Apple identified the bug as a cookie management issue, and patched it by improving the state management.

Now, the security fixes aren’t exclusive to Intel-Macs, though the issues themselves were exploited on those machines. Since the exploits exist in Safari, other devices could also be vulnerable, which is why the patches are included for all Macs that support macOS Sequoia. The security updates have also been released for older Macs running on Ventura and Sonoma, but not as an operating system update. Instead, Apple has released an update for its browser to patch the vulnerabilities on older systems, it bumps the version number to Safari 18.1.1.

There are still quite a few Intel Macs that are supported by macOS Sequoia, these include the 2017 iMac Pro, 2018 Mac mini, 2018 MacBook Pro, 2019 iMac, 2019 MacBook Pro, 2020 iMac, 2020 MacBook Air, and the 2019 Mac Pro. Apple began switching to Apple Silicon chips in 2020, and began phasing out the Intel models. The Cupertino company stopped selling Intel Macs in 2023, the last devices of these to be discontinued was the Mac Pro.

Security fixes for iOS and iPadOS

These patches are also available through visionOS 2.1.1 update for Vision Pro, iOS 18.1.1 for iPhone XS and later, and iPadOS 18.1.1 for iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later. Users on iOS 17 and iPadOS 17 also get the security updates via iOS 17.7.2 (iPhone XS and later), and iPadOS 17.7.2 (all the above-mentioned iPads, plus the iPad 6th generation).

It is advised to update your Mac, iPhone, and iPad as soon as possible, to protect it from the vulnerabilities.

It might seem strange why these zero-day threats are not updated via the Rapid Security Responses system, it was after all designed to counter threats quickly with a small update, and a system reboot. Apple used the RSR system just twice, it appeared to function fine when the company released an RSR update for iOS 16.4.1, iPadOS 16.4.1 and macOS 13.1.1 Ventura in May last year. But, the iOS 16.5.1, iPadOS 16.5.1 and macOS 13.4.1 RSR updates which were released in July 2023 were buggy and broke compatibility with many websites making them unusable, and Apple had to hastily pull the updates. We haven’t seen any RSR updates since then.

Summary

Article Name

Apple patches 2 zero-day vulnerabilities used to attack Intel-based Macs

Description

Attackers are targeting 2 security vulnerabilities in Intel Macs. Update your machine now.

Author

Ashwin

Publisher

Ghacks Technology News

Logo

Advertisement

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

AWS and Bellevue University Collaborate to Boost Cloud Computing Education and Careers Ali Guerra | ...
Microsoft Announces Windows 365 Link, Cloud-Based Desktop PC Resembling Mac Mini Hallie Frederick | ...
The Acer Chromebook Plus 514 review: if you like Chromebooks but want more Ali Guerra | usagoldmines...
Microsoft confirms a Windows 11 bug that blasts your ears at 100% volume if you do these things Hall...
Economic development bill green-lights investments across Western Massachusetts Ali Guerra | usagold...
39 years of Microsoft Windows: A Laptop Mag retrospective Hallie Frederick | usagoldmines.com
Confidential Computing Market Growth Size, Opportunities, Future Scope, Business Scenario, Share, Ke...
Zettar Advances Data Movement in Collaboration with MiTAC Computing and NVIDIA Ali Guerra | usagoldm...
Windows Recall will be disabled by default on enterprise PCs Hallie Frederick | usagoldmines.com
Google’s research on quantum error correction Ali Guerra | usagoldmines.com
Chromebooks running Android could finally make our phone-as-desktop dreams a reality Hallie Frederic...
Microsoft confirms full-screen Windows 11 Copilot+ PCs ads on Windows 10 Hallie Frederick | usagoldm...
Empowering Your Creativity: The STM32 Summit Ali Guerra | usagoldmines.com
Microsoft confirms full-screen Windows 11 Copilot+ PCs ads on Windows 10 Hallie Frederick | usagoldm...
Microsoft confirms you can’t download some Windows 11 widgets now for the good Hallie Frederick | us...
Apple releases iOS 18.1.1, iPadOS 18.1.1, and macOS Sequoia 15.1.1 updates, focuses on security fixe...
Eviden to Deliver Finland’s Next National AI Supercomputer Tripling Its Computing Power Ali Guerra |...
Make Sure to Update: iOS 18.1.1 and macOS Sequoia 15.1.1 Fix Actively Exploited Vulnerabilities Chri...
Microsoft is Launching Automatic Quest 3 Pairing on Windows 11 PCs in December Hallie Frederick | us...
Apple patches 2 zero-day vulnerabilities used to attack Intel-based Macs Renato Bond | usagoldmines....
Context Aware Computing Market Analysis By Top Keyplayers – Ali Guerra | usagoldmines.com
5 alarming Windows cybersecurity facts you probably don’t know Hallie Frederick | usagoldmines.com
Infineon, Quantinuum Partner to Advance Quantum Computing Ali Guerra | usagoldmines.com
Best early Black Friday deals under $100: Amazon Echo, TVs, headphones Macky Briones | usagoldmines....
Microsoft now testing hotpatch on Windows 11 24H2 and Windows 365 Hallie Frederick | usagoldmines.co...
Android 16 Developer Preview 1 is here with new features and a snappier release timeline Chris Mende...
Microsoft and Meta Are Bringing Windows 11 to the Quest 3 Hallie Frederick | usagoldmines.com
MiTAC Computing Unveils New AI/HPC-Optimized Servers with Advanced CPU and GPU Integration at SC24 A...
The Microsoft 365 Companions app will allow you to display important data with a single click on the...
Hurry! The M4 MacBook Pro just got an unheard of discount Ali Guerra | usagoldmines.com
The Microsoft 365 Companions app will allow you to display important data with a single click on the...
LIFE IS STRANGE: DOUBLE EXPOSURE HEADS TO NINTENDO SWITCH eSHOP ON NOV. 19 Hallie Frederick | usagol...
The intersection of AI, blockchain, and cloud computing: Unlocking new business models Ali Guerra | ...
Apple to discontinue iCloud backup support for devices running iOS 8 or earlier in December Renato B...
Understanding Probabilistic and Thermodynamic Computing Ali Guerra | usagoldmines.com
Jensen Huang Predicts a “Millionfold” Increase in Compute in 10 Years Ali Guerra | usagoldmines.com
Microsoft man on how the Windows 95 setup worked • The Register Hallie Frederick | usagoldmines.com
Succeeding with observability in the cloud Ali Guerra | usagoldmines.com
Windows on Arm got another boost with support from this cloud powerhouse you love Hallie Frederick |...
7 Little-Known Windows Features to Save Time Hallie Frederick | usagoldmines.com
Cape Girardeau Police Dept. to upgrade body cameras, car computers Ali Guerra | usagoldmines.com
Axiomtek Debuts P117-ADL-TRA Panel PC with PCIe Expansion Ali Guerra | usagoldmines.com
The M4 Macs have one flaw that may make you reconsider buying one Renato Bond | usagoldmines.com
Apple Dropping Support for iCloud Backups on iPhones and iPads Running iOS 8 and Earlier Renato Bond...
CS professor Billy Moses has received the 2024 SIGHPC Doctoral Dissertation Award | Siebel School of...
Twitter-replacement Bluesky just got its first native Windows 11, and it looks great Hallie Frederic...
Windows 11 multitasking is about to get even better Ali Guerra | usagoldmines.com
Microsoft Windows 11 Pro is 90% off Hallie Frederick | usagoldmines.com
Samsung Galaxy Book5 Pro 360 review: as small as it is big Ali Guerra | usagoldmines.com
IBM Continues Its Progress Towards Creating Useful Quantum Computing Systems Ali Guerra | usagoldmin...
How to upgrade an ‘incompatible’ Windows 10 PC to Windows 11: Two ways Hallie Frederick | usagoldmin...
The best device for playing PC games is finally coming to Australia Hallie Frederick | usagoldmines....
Windows 10 KB5048239 causes 0x80070643 error but Microsoft already has an official fix Hallie Freder...
Bangkok Post – ZTE Showcases Cutting-Edge Solutions at Thailand Convention Ali Guerra | usagoldmines...
Here’s How I Set Up a Secure Guest Account on My Windows PC Hallie Frederick | usagoldmines.com
ZTE unveils industry’s first SPN computing power dedicated line CPE with built-in AI inference Ali G...
This unofficial tool lets you strip Windows 11 24H2 of its bloatware Hallie Frederick | usagoldmines...
Georgia Tech HPC Community Shines at Supercomputing Conference Ali Guerra | usagoldmines.com
Windows 11 Pro Is Being Given Away, This Legal Version Is 90% Off Ahead of Black Friday Hallie Frede...
Why Do PC Gamers Have to Wait for New Games? Hallie Frederick | usagoldmines.com
5 laptops to buy instead of the M4 MacBook Pro Ali Guerra | usagoldmines.com
Register Renaming: The Art Of Parallel Processing Ali Guerra | usagoldmines.com
Upgrade to Windows 11 Pro for $18 – the lowest price this year Hallie Frederick | usagoldmines.com
Windows 11 Blue Screen with QR Code Hallie Frederick | usagoldmines.com
Opinion | The Future Of Disaster Prediction: Quantum Computing And The Power Of Satellites Ali Guerr...
Mechanical keyboards are dead — here’s why you should only buy a magnetic keyboard for gaming Ali Gu...
PC Gamers Technically Have 11 Free Games to Claim Right Now Hallie Frederick | usagoldmines.com
Wait, what? Windows 11 Pro is just £14.24 for life. Hallie Frederick | usagoldmines.com
5 Ways to Create a Local User Account on Windows 11 Hallie Frederick | usagoldmines.com
a historic first for Windows on Arm, a nitrogen-cooled Pi, and more Hallie Frederick | usagoldmines....
Oak Ridge National Laboratory RFI Intends to Strengthen Quantum Research Through Stakeholder Collabo...
Microsoft finally lets users reinstall Windows on Arm, and I hope Boot Camp makes a comeback Hallie ...
Concord Monitor – Thomas Kurtz, Dartmouth co-creator of computer language BASIC, has died Ali Guerra...
How to turn on Bluetooth in Windows and connect your devices Macky Briones | usagoldmines.com
Rigetti Computing Reports on Its Q3 2024 Financial Results Ali Guerra | usagoldmines.com
Windows 11 KB5046716 experiments with new Snap Layouts features Hallie Frederick | usagoldmines.com
GAO: Report Urges Federal Agencies to Address Restrictive Software Licensing Practices in Cloud Comp...
Readers ask about self-correcting quantum computers, oobleck’s experimental value Ali Guerra | usago...
This Week’s Awesome Tech Stories From Around the Web (Through November 16) Ali Guerra | usagoldmines...
Thomas E. Kurtz, co-creator of BASIC programming language, dies at 96 Ali Guerra | usagoldmines.com
Microsoft improves Windows 11 Setup, Recovery with KB5046915 / KB5046910 / KB5046906 Hallie Frederic...
Bytes Managed IT Donates Computers to Aging Office of Western Nebraska Ali Guerra | usagoldmines.com
F-35 Pilots Describe Aircraft, Weapons, Electronics & Computing Ali Guerra | usagoldmines.com
Half-Life 2 gets a major 20th Anniversary Update and bundles Lost Coast with episodes —the game is n...
Palm OS phones were Android before there was Android Hallie Frederick | usagoldmines.com
QNu Labs plans geographical expansion Ali Guerra | usagoldmines.com
How to Fix File Explorer Issues on Windows 11 Hallie Frederick | usagoldmines.com
TUXEDO Computers Relicenses Some Of Their Drivers To GPLv2 Ali Guerra | usagoldmines.com
Nvidia’s Quantum Computing Surprise. What It Means for Our Future. Ali Guerra | usagoldmines.com
I don’t know how I used Windows 11 before these 7 PowerToys apps Hallie Frederick | usagoldmines.com
I tried 4 different gaming mice. Only one was worth keeping Ali Guerra | usagoldmines.com
ZTE unveils G6 series servers in overseas markets to enhance efficient and green computing power inf...
Free tool allows Windows 10 File Explorer (Search) in Windows 11 and more, without Registry Hallie F...
Quick Share for Windows is coming to ARM-powered PCs Hallie Frederick | usagoldmines.com
Embedded Computing Market Size to worth US$ 174.38 Billion by 2031, Coherent Market Insights Ali Gue...
Could Quantum Computers Spell Danger for Your Crypto? Ali Guerra | usagoldmines.com
Microsoft confirms mistake in Windows 11 update causing false “end-of-support” alerts Hallie Frederi...
Valve just unveiled a white Steam Deck OLED, but you’ll need to order it quickly Hallie Frederick | ...
RIKEN, NTT, and Fixstars Launch World’s First General-Purpose Optical Quantum Computing Platform Ali...
How quantum computing could reshape financial services Ali Guerra | usagoldmines.com

Leave a Reply