Apple patches three exploited Safari vulnerabilities

Attackers, whose identities remain unknown, have exploited vulnerabilities in Apple’s Safari browser’s WebKit engine, which is utilized for rendering web content across the company’s operating systems. One of the vulnerabilities allowed attackers to bypass the protective “sandbox” that restricts access to other parts of the operating system. This specific vulnerability, identified as CVE-2023-32409, has been patched in the latest security updates released by Apple. The attacks and the suspected culprits have not been disclosed by Google’s Threat Analysis Group (TAG), Amnesty International, or Apple.

Apple also addressed two other vulnerabilities in WebKit through its Rapid Security Response out-of-band patches. These vulnerabilities, reported by anonymous researchers, enabled attackers to access sensitive information and execute arbitrary code by exploiting an out-of-bounds read flaw and a use-after-free condition.

Furthermore, security researcher Amat Cama of Vigilant Labs discovered a bug in the cellular function of iPhone 8 and X, which could be exploited to remotely execute arbitrary code. Ivan Fratric from Google’s Project Zero identified a flaw in the Telephony function of iPhone 8 and later models, iPad Pro, Air, and mini, which could crash applications and also be abused for remote code execution.

Apple has released security updates for various systems, including Safari web browser, watchOS, tvOS, iOS, iPadOS, and macOS.

Akshara Krishnan
Akshara Krishnan
Akshara Krishnan is passionate content and copywriter, who is highly interested and competent in the fields of digital marketing and supply chain management. She is an avid reader who enjoys books on self-help and psychology, and actively partakes in classical singing.

Similar Articles

Comments

Most Popular