Apple says Mac users targeted in zero-day cyberattacks

Date:

Share post:


Apple released security updates on Tuesday that it says are “recommended for all users,” after fixing a pair of security bugs used in active cyberattacks targeting Mac users.

In a security advisory on its website, Apple said it was aware of two vulnerabilities that “may have been actively exploited on Intel-based Mac systems.” The bugs are considered “zero day” vulnerabilities because they were unknown to Apple at the time they were exploited.

To fix the bugs, Apple released a software update for macOS, as well as fixes for iPhones and iPads, including users running the older iOS 17 software.

It’s not yet known who is behind the attacks targeting Mac users, or how many Mac users have been targeted — or if any were successfully compromised. The vulnerabilities were reported by security researchers at Google’s Threat Analysis Group, which investigates government-backed hacking and cyberattacks, suggesting that a government actor may be involved in the attacks. Government-backed cyberattacks sometimes involve the use of commercial phone spyware.

As for the bugs themselves, Apple said the vulnerabilities relate to WebKit and JavaScriptCore, the web engines that power the Safari browser and for running web content. WebKit is a frequent target of malicious hackers, who target the engine for vulnerabilities as a way to break into the device’s wider software and tap into the user’s private data.

The security advisory says the bugs can be exploited by tricking vulnerable Apple devices into processing maliciously crafted web content, such as a website or email, to trigger arbitrary code execution, which can allow the planting of malware on a target’s device. 

Users should update their iPhones, iPads, and Macs as soon as possible. 

Apple did not comment when contacted by TechCrunch on Tuesday. 



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Bluesky adds mentions tab in the notifications screen and username squatting protection

Social network Bluesky has released a new update to its app that includes a separate mentions tab...

Uzbekistan’s mobile bank TBC bags $37M to expand with new AI and insurance products

Uzbekistan’s mobile-exclusive bank, TBC Bank Uzbekistan, has raised $37 million in a new funding round to bolster...

British university spinoff Mindgard protects companies from AI threats

AI creates a dilemma for companies: Don’t implement it yet, and you might miss out on productivity...

European Solo GP Robin Capital closes first fund with €15M to play with

Robin Capital — the Germany-based, Solo GP-led VC fund by former entrepreneur Robin Haak — has hit...

Sequoia’s Matt Miller is exiting the firm after making headlines earlier this year

The writing was on the wall, seemingly.  Sequoia Capital partner Matt Miller announced on Wednesday that he’s leaving...

India’s Rapido exposed user and driver data through leaky website feedback form

Rapido, a popular ride-hailing platform in India, has fixed a security issue that exposed personal information associated...

Sam Altman once owned some equity in OpenAI through Sequoia

OpenAI CEO Sam Altman sat before Congress in 2023 to testify about the dangers of AI. He...

Perplexity has reportedly closed a $500M funding round

AI-powered search engine Perplexity has reportedly closed a $500 million funding round, valuing the startup at $9...