*** TDS Newsflash ***

More Apple Vulnerabilities

Please update any Apple device you own by checking for any updates.

MS-ISAC ADVISORY NUMBER:

2021-137

DATE(S) ISSUED:

10/27/2021

SUBJECT:

Multiple Vulnerabilities in Apple Products Could Allow for Arbitrary Code Execution.

OVERVIEW:

Multiple vulnerabilities have been discovered in Apple Products, the most severe of which could allow for arbitrary code execution.

  • iOS is a mobile operating system for mobile devices, including the iPhone, iPad, and iPod touch.
  • iPadOS is the successor to iOS 12 and is a mobile operating system for iPads.
  • macOS Monterey is the 18th and current major release of macOS.
  • macOS Big Sur is the 17th release of macOS.
  • macOS Catalina is the 16th major release of macOS
  • watchOS is the mobile operating system for Apple Watch and is based on the iOS operating system.
  • tvOS is an operating system for fourth-generation Apple TV digital media player.

Successful exploitation of the most severe of these vulnerabilities could result in arbitrary code execution within the context of the application, an attacker gaining the same privileges as the logged-on user, or the bypassing of security restrictions. Depending on the permission associated with the application running the exploit, an attacker could then install programs; view, change, or delete data.

THREAT INTELLIGENCE:

There are no reports of these vulnerabilities being exploited in the wild.

                                                                                                     

SYSTEMS AFFECTED:

  • iOS and iPadOS prior to 15.1
  • iOS and iPadOS prior to 14.8.1
  • macOS Monterey prior to 12.0.1
  • macOS Big Sur prior to 11.6.1
  • macOS Catalina prior to security update 2021-007
  • watchOS prior to 8.1
  • tvOS prior to 15.1

RISK:

Government:

  • Large and medium government entities: High
  • Small government entities: Medium

Businesses:

  • Large and medium business entities: High
  • Small business entities: Medium

Home users: Low


Thank you, and if there are any questions, please let us know, by forwarding this email to help@techspert-data.com or calling our office at (330) 441-4426.

Have a great day and thank you for giving us the privilege of serving you!