Wednesday, January 8, 2025
HomeSecurity NewsApple Released a Critical Security Updates for iOS 11.2.1

Apple Released a Critical Security Updates for iOS 11.2.1

Published on

Apple released a new Critical security update for iOS 11.2.1 and Apple products such as tvOS, watchOS, macOS.

This Apple security update for remote attack flaw that leads to an attacker may be able to unexpectedly alter application state.

Improper input validation was the root cause of this vulnerability and Message handling issue was addressed with improved input validation.

This update available for iPhone 5s and later, iPad Air and later, and iPod touch 6th generation.

Apple tvOS 11.2.1

Security patch also released for Apple TV 4K and Apple TV (4th generation) and the same vulnerability has been discovered for this Apple TV based.

Security Researcher Tian Zhang has been reported this vulnerability to Apple and CVE-2017-139;03 has been assigned.

Also Read:  Microsoft Released New Security Patch Updates for More than 30 Critical Security Issues

Apple  iCloud for Windows 7.2

A vulnerability that discovered in APNs Server Leads to an attacker in a privileged network position can track a user which has been identified in the use of client certificates with help of revised protocol.

A team(FURIOUSMAC ) from  United States Naval Academy has reported this vulnerability to apple and CVE-2017-13864 has been Assigned.

Also, another critical vulnerability Discovered that performs maliciously crafted web content may lead to arbitrary code execution.

This vulnerability has been patched and adds into common vulnerability database.

  • CVE-2017-7156: an anonymous researcher
  • CVE-2017-7157: an anonymous researcher
  • CVE-2017-13856: Jeonghoon Shin
  • CVE-2017-13870: an anonymous researcher
  • CVE-2017-13866: an anonymous researcher
Name and information linkAvailable forRelease date
iCloud for Windows 7.2Windows 7 and later13 Dec 2017
tvOS 11.2.1Apple TV 4K and Apple TV (4th generation)13 Dec 2017
iOS 11.2.1iPhone 5s and later, iPad Air and later, and iPod touch 6th generation13 Dec 2017

Keeping your software up to date is one of the most important things you can do to maintain your Apple product’s security. Apple said.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

New WordPress Plugin That Weaponizes Legit Sites To Steal Customer Payment Data

Cybercriminals have developed PhishWP, a malicious WordPress plugin, to facilitate sophisticated phishing attacks, which...

New FireScam Android Malware Abusing Firebase Services To Evade Detection

FireScam is multi-stage malware disguised as a fake “Telegram Premium” app that steals data...

Hackers Weaponize Security Testing By Weaponizing npm, PyPI, & Ruby Exploit Packages

Over the past year, malicious actors have been abusing OAST services for data exfiltration,...

Hackers Mimic Social Security Administration To Deliver ConnectWise RAT

A phishing campaign spoofing the United States Social Security Administration emerged in September 2024,...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome...

North Korean Hackers Stolen $2.2 Billion From Crypto Platforms In 2024

Cryptocurrency hacking incidents in 2024 surged 21.07% YoY to $2.2 billion, with 303 breaches...

Deloitte Denies Breach, Claims Only Single System Affected

Ransomware group Brain Cipher claimed to have breached Deloitte UK and threatened to publish...