If you're the owner of an iPhone, iPad, or Apple Mac you should update your system right now.
Apple has released a major security update for its devices, after finding a zero-day flaw that the company indicates has been the focus of in-the-wild attacks by hackers, and might have been used to plant malware.
As is its wont, Apple has not released any real details about the flaw, presumably in an attempt to reduce the chances of other parties exploiting the security vulnerability.
According to a security advisory published on Apple's website, the flaw - technically known as CVE-2021-30807 - was reported to the firm by an anonymous researcher, and involves a memory corruption flaw
in the IOMobileFrameBuffer kernel extension used for managing the screen framebuffer, that can be abused to execute arbitrary code on a device with kernel privileges.
If a malicious hacker's code successfully gains kernel privileges it seizes God-like control over the device.
What makes things all the more serious is Apple's warning that the security flaw has been used in real-world attacks:
“Apple is aware of a report that this issue may have been actively exploited.”
Proof-of-concept code to exploit the flaw has been published on Twitter
Users are advised to update to the latest versions of iOS (14.7.1), iPadOS (14.7.1), and macOS (11.5.1) to protect against the issue.
Another security researcher, Saar Amar, claims to have also uncovered the vulnerability four months ago, although he had not yet reported it to Apple as he was still working on methods to exploit the flaw. Amar described the vulnerability as being "as trivial and straightforward as it can get."
With details of how to exploit the vulnerability published in the wild, and Apple's claims that it has been actively exploited, there really is no time to wait - everyone should update their Apple devices.
To update your Mac or MacBook, choose System Preferences from the Apple menu in the top-left of the screen. Then click Software Update to see if any updates are available and follow instructions.
If your iPhone or iPad has not yet installed the latest security update, open Settings, and choose General > Software Update and follow instructions.
tags
Graham Cluley is an award-winning security blogger, researcher and public speaker. He has been working in the computer security industry since the early 1990s.
View all postsDecember 19, 2024
November 14, 2024