/?pid=22927

Updated:06:47 PM EDT Apr 24


this is ggmania.com subsite Apple rushes out iOS 15.0.2 just hours after 15.0.1 - TechAmok

Apple rushes out iOS 15.0.2 just hours after 15.0.1 - [security]
07:55 AM EDT - Oct,14 2021 - post a comment

On Monday, Apple issued an urgent security fix for a zero-day flaw in iOS 15 and iPadOS 15 that hackers are actively exploiting. The patch came the same day it released iOS 15.0.1. The bug (CVE-2021-30883) causes a memory-corruption error in the IOMobileFrameBuffer, a kernel function that allows developers to allocate how their apps use system memory to control the display. "An application may be able to execute arbitrary code with kernel privileges," read Apple's patch notes. "Apple is aware of a report that this issue may have been actively exploited." The patch notes did not go into great detail about the bug. However, shortly after Apple released iOS and iPadOS 15.0.2, security researcher Saar Amar published a blog post explaining the exploit and created a proof-of-concept (POC) to show that it works "100 percent of the time." Amar said the flaw is "great for jailbreaks" because it is accessible from the app sandbox.

After examining the BinDiff (a tool that shows differences in disassembled binaries), Amar concluded that the flaw was not just good for granting kernel privileges but could also be used for LPE (local privilege escalation) exploits. He tested his very simple (one page of code) POC on iOS versions 14.7.1 (physical iPhone X) and 15.0 (virtual iPhone 11 Pro) but said the bug is likely much older than that. He ran the code five times on each device, and the POC triggered a panic in every instance. Amar's code caused integer overflows in areas other than the IOMobileFrameBuffer, but the patch also seems to have corrected those. "An interesting important note is that other implementations of these functions in other classes also had this integer overflow," Amar wrote. "As far as I can see, the patch fixed these as well."

Aside from the jailbreaking potential, this security flaw is similar to the nasty one (CVE-2021-30807) that Apple patched in July. Malicious attackers could use the bug to hijack the device completely (and apparently are). So it's best to install the patch as soon as possible.


Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,24 2024 President Biden signs TikTok bill into law
Apr,24 2024 The Humble PC
Apr,24 2024 Researchers have unlocked the 'Holy Grail' of memory technology
Apr,24 2024 The Best Gaming GPU Ever Released, Nvidia GeForce GTX 1080 Ti, 2024
Apr,24 2024 Your Own Private Network Attached Storage Solution by UGREEN
Apr,23 2024 ATLAS | Official Trailer | Netflix
Apr,22 2024 The World's Fastest CPU (Technically...) - Intel i9-14900KS
Apr,22 2024 We can do THIS now! - Lumafield CT Scanner
Apr,21 2024 Huawei Pura 70 Ultra - Apple Should be WORRIED
Apr,21 2024 Sony 2024 TV Lineup Revealed
Apr,20 2024 ICE - A Thousand Suns / Episode 1
Apr,20 2024 Minisforum V3 AMD Tablet Review
Apr,20 2024 AMD & Intel SLASH CPU Prices!
Apr,20 2024 EK is Imploding: Not Paying Employees, Partners, & Suppliers
Apr,20 2024 Backing Up My NAS To My... Parents' House?
Apr,20 2024 NEW Ryzen APU BEATS RTX 40 GPUs!
Apr,20 2024 (Live) Black Tape Project - All New Raw and Uncut - LA Fashion Week
Apr,19 2024 NVIDIA Geforce 552.22 WHQL Driver
Apr,19 2024 You Deserve this much OLED - AORUS CO49DQ
Apr,19 2024 Unreal Engine 5.4 looks ULTRA PHOTOREALISTIC
Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs