Sujet : Re: Install iOS 17.4.1 now to patch 2 new zero-day vulnerabilities
De : enrico (at) *nospam* papaloma.net (Enrico Papaloma)
Groupes : misc.phone.mobile.iphone comp.mobile.ipadDate : 24. Apr 2024, 20:44:25
Autres entêtes
Organisation : Gegeweb News Server
Message-ID : <v0bnep$5d6$1@news.gegeweb.eu>
References : 1 2
User-Agent : Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Thunderbird/102.6.1?Content-Type: text/plain; charset=UTF-8; format=flowed
On 4/24/2024 4:51 PM, Chris wrote:
Install iOS 17.4.1 now to patch 2 new zero-day vulnerabilities.
You're a month late. 17.4.1 was released a month ago.
The article is dated "April 24, 2024 3:00 a.m. PT" as it's advice to people
who would normally skip the 17.4.1 release since many people wait for 17.5.
The advice is that these iOS zero-day holes that Apple didn't find are so
severe, the recommendation is for iPhone owners to update even if they were
intending to wait for iOS 17.5 before running yet another update cycle.
These are the 2 0-day holes that Google found that Apple missed in testing.
CoreMedia
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and
later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad
Air 3rd generation and later, iPad 6th generation and later, and iPad mini
5th generation and later
Impact: Processing an image may lead to arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved input
validation.
CVE-2024-1580: Nick Galloway of Google Project Zero
WebRTC
Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and
later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad
Air 3rd generation and later, iPad 6th generation and later, and iPad mini
5th generation and later
Impact: Processing an image may lead to arbitrary code execution
Description: An out-of-bounds write issue was addressed with improved input
validation.
CVE-2024-1580: Nick Galloway of Google Project Zero
What is arbitrary code execution?
https://www.okta.com/identity-101/arbitrary-code-execution/