iTnews Asia
  • Home
  • News
  • Security

Apple patches 2024's first zero-day

Apple patches 2024's first zero-day

Exploited Webkit vulnerability in MacOS, iOS and iPadOS.

By Richard Chirgwin on Jan 24, 2024 12:43PM

Apple’s first zero-day of 2024 has been disclosed, with fixes pushed out for MacOS, iOS, and iPadOS.

Apple’s description of CVE-2024-23222 states only that the bug is a type confusion in Webkit, and that the company “is aware of a report that this issue may have been exploited”.

“Processing maliciously crafted web content may lead to arbitrary code execution”, Apple noted.

Fixes have been published for iPhones and iPads, and Macs running macOS Ventura and Monterey.

Apple also applied a patch to a critical-rated bug in the curl URL retrieval library that was first disclosed during 2023.

CVE-2023-38545 (CVSS score 9.8) is a heap-based buffer overflow during the SOCKS5 proxy handshake, described in detail by the curl project here.

It’s one of four curl bugs updated in Ventura and Monterey by updating to curl version 8.4.0.

Other fixes in the security roll-up plug bugs in the Apple Neural Engine, accessibility features, core data, finder, ImageIO, the login window, Apple Mail search, and the NSOpenPanel function in AppKit.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apple ios macos security zeroday

Related Articles

  • Best practice tips for secure password management
  • Are third-party blind spots the weakest link in enterprise cybersecurity chain?
  • Five tips a CIO or CSO should know to stop employee-driven IP theft
  • StarHub launches app to protect customers from scam calls and SMS
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Are third-party blind spots the weakest link in enterprise cybersecurity chain?

Malaysia's Maxis Berhad investigates claims on alleged data breach

Malaysia's Maxis Berhad investigates claims on alleged data breach

Philippine education ministry hit by data leak exposing 210,020 records

Philippine education ministry hit by data leak exposing 210,020 records

PhilHealth estimates 13 to 20 million members affected by data breach

PhilHealth estimates 13 to 20 million members affected by data breach

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.