Apple reveals it patched even more security flaws than previously thought

Hand increasing the protection level by turning a knob
(Image credit: Shutterstock)

Apple has admitted that its latest iOS and iPadOS 16.3 update addressed several more vulnerabilities than the company initially reported.

The change was spotted by AppleDB contributor Aaron, who in a recently posted tweet noted that Apple had added a new Common Vulnerabilities and Exposures (CVE) for iOS 16.3.1, as well as three additional CVEs for iOS 16.3, released earlier this year to the list of noted security flaws that the company has successfully patched.

For iOS 16.3.1, Apple now said it also fixed a “maliciously crafted certificate” vulnerability that allowed threat actors to initiate denial-of-servie (DoS) attacks. The flaw was fixed with “improved input validation”, Apple said.

No explanations

As for iOS 16.3, one of the flaws allowed threat actors to read arbitrary files as root. The other two were related to Foundation, and could allow threat actors to bypass the app sandbox and run arbitrary code on the endpoints with elevated privileges.

Apple gave no explanation why it failed to add these vulnerabilities before. For all we know, it might just be an erroneous omission. Whatever the reason, iOS and iPad OS devices running the 16.3.1 version are safe from all of them, so it’s worth updating as quickly as possible. 

For macOS 13.2.1 and iOS 16.3.1, Apple also addressed a WebKit vulnerability allegedly being exploited in the wild, 9To5Mac reported. The full breakdown of all the vulnerabilities patched in the latest versions of iOS can be found on this link.

iOS 16.3 was released on January 23, 2023, with Advanced Data Protection, Security Keys, new wallpapers, and support for the HomePod 2.

It's a release that brings improvements to many apps, from a redesigned Home app for your smart appliances to better privacy features, and a big focus on the lock screen, with new fonts, colors and themes to choose from.

Via: 9To5Mac

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock