iOS 18.4.1 patches two iPhone security flaws used in 'extremely sophisticated' attacks

On Wednesday, Apple pushed updates to most of its platforms: iOS 18.4.1, iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1 and visionOS 2.4.1. They contain two security fixes for flaws that may have been used in real-world attacks, so it's wise to update your devices without too much delay.

Apple is aware of a report that both security issues "may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

One patched bug is in Apple's audio framework, CoreAudio. This memory corruption issue allowed malicious media files to execute code when processed as audio streams. The other relates to the Remote Participant Audio Control (RPAC) framework, which lets communications apps manage audio streams. That flaw allowed an attacker with arbitrary read / write capabilities to bypass Pointer Authentication (a security feature in Apple's processors).

Apple "strongly advises" all users to update their devices.

This article originally appeared on Engadget at https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss
Created 3mo | Apr 16, 2025, 8:50:11 PM


Login to add comment

Other posts in this group

Opera takes its browser beef with Microsoft to Brazil in antitrust complaint

Opera is filing an antitrust complaint against Microsoft in Brazil,

Jul 29, 2025, 11:50:15 PM | Engadget
Home Depot has a new animatronic version of Skelly the skeleton

The Home Depot is well on its way to becoming a Spirit Halloween that also sells weed whackers. Here we are in July, and the retailer is already

Jul 29, 2025, 7:20:45 PM | Engadget
ChatGPT's Study Mode will guide students to an answer stey by step

OpenAI is rolling out a new Study Mode the company says is designed to give students a better understa

Jul 29, 2025, 7:20:42 PM | Engadget
Google adds Video Overviews to NotebookLM

NotebookLM, the Google research tool that gained notoriety for its

Jul 29, 2025, 7:20:40 PM | Engadget
YouTube is turning over age verification to AI

YouTube will start using machine learning to determine whether viewers should be on a teen account. The company

Jul 29, 2025, 7:20:39 PM | Engadget
Prime members can get the DJI Mini 4K drone on sale for $249

Amazon is selling the

Jul 29, 2025, 5:10:23 PM | Engadget
Our favorite Logitech mouse is $40 off right now

If you're in the market for a new mouse that won't totally break the bank then today is your lucky day. Right now,

Jul 29, 2025, 5:10:22 PM | Engadget