Apple patched an issue in macOS that was actively exploited

The details of an actively exploited vulnerability in Apple’s older macOS Big Sur operating system were initially made public in April.

MacOS Monterey, iPadOS, and iOS all received updates for two actively exploited vulnerabilities at the time, while macOS Big Sur did not.

Apple users were notified in April by the Cybersecurity and Infrastructure Security Agency (CISA) that they needed to patch against two actively exploited vulnerabilities.

“An attacker might use one of these flaws to gain control of a vulnerable device.”

In an April advisory, CISA stated, “These vulnerabilities have been found in exploits in the field.”

In their May 2022 round of security updates, Apple noted that one hole in the AppleAVD media file decoder may have been actively exploited, and provided an extra patch for Big Sur.

Apple and CISA both declined to say when or where the bug was exploited.

According to Apple’s caution, the earlier macOS Catalina operating system is not vulnerable to the AppleAVD problem, but it has gotten 38 patches for various CVEs.

MacOS Monterey has been upgraded to version 12.4, which includes security patches for 73 vulnerabilities.

While Apple does not provide severity ratings to the vulnerabilities it fixes, the SANS Internet Storm Centre has classified ten of the 86 problems as severe, meaning they can be exploited to execute arbitrary code.

ImageIO, libXML2, Webkit, AppleGraphicsControl, Intel Graphics driver, libresolv, zlib, and SMB operating system components all have remote code execution.

Akshara Krishnan
Akshara Krishnan
Akshara Krishnan is passionate content and copywriter, who is highly interested and competent in the fields of digital marketing and supply chain management. She is an avid reader who enjoys books on self-help and psychology, and actively partakes in classical singing.

Similar Articles

Comments

Most Popular