Apple Fixes New Zero-Day Used in Attacks Against iPhones, Macs
Cyber Security Threat Summary:
Apple has released security updates to address a zero-day vulnerability that was exploited in attacks targeting iPhones, Macs, iPads. Tracked as CVE-2023-38606, the flaw relates to a shortcoming in the kernel that could allow a malicious application to potentially modify sensitive kernel states. The flaw was fixed with improved checks with updates being released for the following devices and operating systems:
Security Officer Comments:
Apple says it is aware that the flaw may have been actively exploited against versions of iOS released before iOS 15.7.1. As of writing, the technical details have been released to give users enough time to apply the updates. However, according to security experts at Kaspersky, CVE-2023-38606 was used as part of a zero-click exploit chain to deploy Triangulation spyware on iPhones via iMessage exploits.
Suggested Correction(s):
Users are advised to apply the latest updates as soon as possible to prevent potential exploitation attempts.
Link(s):
https://www.bleepingcomputer.com/