In today's iOS 14.4 update, Apple fixes three 0-days, tipped by an anonymous researcher, and acknowledges a report that they may have been exploited in the wild
Fixes come after Apple patched another set of three zero-days last November. — Apple has released today security updates …
ZDNetCatalin Cimpanu
Context & Ripple Effects
Apple had already patched three zero-days in November, making iOS 14.4 a second consecutive disclosure involving multiple flaws and a possible real-world exploitation report. The anonymous tip also shows Apple acting on outside vulnerability research rather than a public attribution.
The pattern makes rapid installation more consequential for Apple device users because reported exploitation can precede or accompany public disclosure.
Third-order effects
If this cadence persists, zero-day response becomes a standing cross-platform operating function for Apple rather than an occasional iOS maintenance event.
⚠️ If you are using a mobile crypto wallet on an iOS device, be sure to update iOS as soon as possible! The update includes a fix for a remote arbitrary code execution vulnerability that may have been actively exploited. https://support.apple.com/...
NEW: Apple fixes three iOS zero-days exploited in the wild -one of the zero-days is in the iOS kernel (race condition) -two others impact WebKit (RCE) -zero-days believed to be part of an exploit chain https://www.zdnet.com/... https://twitter.com/...
Apple fixed three security vulnerabilities potentially exploited in the wild, two of them affecting only iOS and iPadOS, while one also impacts tvOS and watchOS. https://support.apple.com/... https://twitter.com/...
🚨Attn iOS Users🚨 Take a moment to update your iOS to 14.4. Apple has released a security update that defends a malicious app vulnerability. https://support.apple.com/...
New: Apple has released a software update for iPhones and iPads that fixes three security flaws, which the company says may be under active attack by hackers. https://techcrunch.com/...
It's always concerning when a kernel exploit is identified by Apple as having “been actively exploited”. 😟 https://support.apple.com/... #HT212146 #ios144 #ipados144 https://twitter.com/...