Powered by MOMENTUM MEDIA
cyber daily logo

Breaking news and updates daily. Subscribe to our Newsletter

Breaking news and updates daily. Subscribe to our Newsletter X facebook linkedin Instagram Instagram

CISA warns of 2 Apple OS bugs being exploited in the wild

The US Cybersecurity and Infrastructure Security Agency has added two new Apple-related vulnerabilities to its catalogue and warned that they are both being actively exploited.

user icon David Hollingworth
Tue, 12 Sep 2023
CISA warns of 2 Apple OS bugs being exploited in the wild
expand image

The first, CVE-2023-41064, is a buffer overflow vulnerability wherein a “maliciously crafted image” could lead to the execution of arbitrary code. This affects Apple products across its range, but it has been fixed in the following OS versions:

  • macOS Monterey 12.6.9
  • macOS Big Sur 11.7.10
  • macOS Ventura 13.5.2,
  • iOS 16.6.1
  • iPadOS 16.6.1
  • iOS 15.7.9
  • iPadOS 15.7.9

The second vulnerability, CVE-2023-41061, is a validation issue that could allow a malicious attachment to lead to arbitrary code execution. This flaw only affects Apple’s mobile devices, but it has been fixed in the following OS versions:

  • watchOS 9.6.2
  • iOS 16.6.1
  • iPadOS 16.6.1

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA said in a statement.

According to CISA, both vulnerabilities are still being analysed, but nonetheless, making sure your affected devices are running up-to-date operating systems should do the trick.

David Hollingworth

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

cd intro podcast

Introducing Cyber Daily, the new name for Cyber Security Connect

Click here to learn all about it
newsletter
cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.