/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple updates iOS, iPadOS, and macOS to address a zero-day flaw that was reportedly actively exploited, making it the 13th zero-day Apple has patched this year

Apple has released patches today for iOS, iPadOS, and macOS to address a zero-day vulnerability that the company says has been exploited in the wild.

The Record Catalin Cimpanu

Context & Ripple Effects

Apple had already acknowledged three potentially exploited iOS flaws in its January iOS 14.4 security update. Reaching a 13th patched zero-day later that year makes the new cross-platform release part of a sustained response cadence rather than an isolated fix.

The same pattern recurs in later coverage: Apple issued multi-platform fixes tied to Pegasus delivery and subsequent emergency updates for additional potentially exploited flaws. The recurring need to patch iOS, iPadOS, and macOS together makes rapid installation central to limiting exposure.

First-order effects

  • Users of iOS, iPadOS, and macOS receive a fix for an actively exploited vulnerability, with protection dependent on installing Apple’s updates.
  • Apple must ship and support an emergency patch across three operating systems while the reported exploit is already in use.

Second-order effects

  • Actors using the reported vulnerability lose a known route into devices as updated Apple users move onto patched versions.
  • Apple’s security-release process becomes more closely tied to coordinated cross-platform updates, since unpatched devices on any of the three systems remain the immediate exposure point.

Third-order effects

  • A repeated stream of exploited-flaw patches points to platform security being defined increasingly by the speed and reach of vendor update delivery, not only by preventive hardening.
  • If the cadence persists, Apple’s ecosystem advantage will increasingly rest on maintaining synchronized security support across its operating systems as exploit disclosures arrive.

The trend: Apple’s security posture is moving toward recurrent, coordinated emergency patching across its device platforms in response to exploited zero-days.

Discussion

  • @amarsaar Saar Amar on x
    So, as it turns out, an LPE vulnerability I found 4 months ago in IOMFB is now patched in iOS 14.7.1 as in-the-wild. I wanted to share some knowledge and details about the bug and some ways to exploit it. Hope you'll find it useful, check it out! https://saaramar.github.io/...
  • @craiu Costin Raiu on x
    Always interesting to keep an eye on iOS bugs for which “Apple is aware this issue may have been actively exploited” and reported by “an anonymous researcher” 🤔
  • @campuscodi Catalin Cimpanu on x
    Apple really hates the jailbreaking community. Passing jailbreaks as actively exploited zero-days is a smart plan to trick users to update to a new release and avoid having them root their devices 😆
  • @maddiestone Maddie Stone on x
    @AmarSaar Thanks for the write-up! Just curious, was there any particular reason you didn't report it?
  • @campuscodi Catalin Cimpanu on x
    There is now a PoC for CVE-2021-30807: https://twitter.com/... I wouldn't rule out that this was a new jailbreaking exploit and not an actual zero-day exploited in the wild. Apple has done this before—passed jailbreaks as zero-days.
  • @cubicleapril April King on x
    Here's an idea: stop writing code that accepts untrusted inputs in memory unsafe languages. https://twitter.com/...
  • @amarsaar Saar Amar on x
    @maddiestone Thanks a lot Maddie! Sure, I wanted to write a full exploit and achieve tfp0 before submitting because it affects the submission quality. I'm pretty busy right now, so I planned to work on it after August. I did plan to submit it, but I wanted to get an exploit first…
  • @xerusdesign Xerus on x
    Seems like todays in the wild bug that was patched in 14.7.1 can achieve tfp0/kernel r/w. Things are looking great for a 14.7 jailbreak assuming someone will pick up the work and build an exploit. 🤞 https://twitter.com/...
  • @datadrivenmd Jorge A. Caballero on x
    That time Apple realized that no amount of sandboxing will keep hackers from turning their products into playgrounds https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Apple released a patch today for an iOS and macOS zero-day, the 13th zero-day detected and patched this year across its products https://therecord.media/... https://twitter.com/...