Apple fixes new security flaw used in ‘extremely sophisticated attack’

Date:

Share post:


Apple released patches for a bug that it says “may have been exploited in an extremely sophisticated attack against specific targeted individuals,” citing a report.

The zero-day bug was found in WebKit, the browser engine powering Safari and other apps, and allowed hackers to break out of WebKit’s protective sandbox with “maliciously crafted web content,” per Apple. A sandbox is part of the operating system that, even if compromised, can keep hackers from accessing data in other parts of the system. 

The patch was released on Tuesday for Macs, iPhones and iPad, Safari, and its Vision Pro headset.

Contact Us

Do you have more information about Apple vulnerabilities, or cyberattacks against Apple users? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Apple noted that the attack was exploited against devices running software “before iOS 17.2.”

Neither the hackers nor their targets were disclosed. Apple did not respond to a request for comment. 

In February, Apple used the same language — “an extremely sophisticated attack against specific targeted individuals” — for another bug, but there is no evidence the two attacks are connected. Before that February patch, Apple had never used this wording before.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

How La Fourche, an online organic supermarket, is thriving after q-commerce’s bust

La Fourche is just seven years old but it has been quite a rollercoaster for the French...

Pentera nabs $60M at a $1B+ valuation to build simulated network attacks to train security teams

Strong and smart security operations teams are at the heart of any cybersecurity strategy, and today a...

Meta faces publisher copyright AI lawsuit in France

Meta is facing an AI copyright publisher lawsuit in France accusing it of economic “parasitism,” Reuters reports. The...

Scimplify raises $40M to help manufacturers access specialty chemicals

Scimplify, an Indian startup that helps pharmaceutical and agriculture companies access a range of specialty chemicals, has...

Salesforce to invest $1B in Singapore to boost adoption of AI

Salesforce plans to invest $1 billion in Singapore over the next five years as it seeks to...

Elea AI is chasing the healthcare productivity opportunity by targeting pathology labs’ legacy systems

VC funding into AI tools for healthcare was projected to hit $11 billion last year — a...

Uber terminates Foodpanda Taiwan acquisition, citing regulatory hurdles

Uber Technologies has ended its acquisition of Delivery Hero’s Foodpanda in Taiwan, the Germany-based tech firm said...

Jio announces deal to bring Starlink to India just hours after similar Airtel partnership

Jio Platforms, the subsidiary of India’s conglomerate Reliance Industries and the country’s largest telecom operator, Wednesday announced...