iOS 18.4.1 patches two iPhone security flaws used in 'extremely sophisticated' attacks

On Wednesday, Apple pushed updates to most of its platforms: iOS 18.4.1, iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1 and visionOS 2.4.1. They contain two security fixes for flaws that may have been used in real-world attacks, so it's wise to update your devices without too much delay.

Apple is aware of a report that both security issues "may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

One patched bug is in Apple's audio framework, CoreAudio. This memory corruption issue allowed malicious media files to execute code when processed as audio streams. The other relates to the Remote Participant Audio Control (RPAC) framework, which lets communications apps manage audio streams. That flaw allowed an attacker with arbitrary read / write capabilities to bypass Pointer Authentication (a security feature in Apple's processors).

Apple "strongly advises" all users to update their devices.

This article originally appeared on Engadget at https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss
Creato 1mo | 16 apr 2025, 20:50:11


Accedi per aggiungere un commento

Altri post in questo gruppo

X is recovering after a data center outage

X seems to finally be recovering from a data center outage that brought down the site for some users Thursday and caused lingering issues into Friday. According

23 mag 2025, 21:10:08 | Engadget
OG Fortnite may have as many as 92 bots per match

Has your competition in Fortnite ever felt a bit… off? If

23 mag 2025, 21:10:06 | Engadget
One of Whoop's new wearables has a bug so bad the company is issuing replacements

Whoop's new screen-less, fitness-focused Whoop MG wearable might have a major bug that can leave the device unusable, according to reports from

23 mag 2025, 21:10:04 | Engadget
Dyson Memorial Day deals include $200 off the 360 Vis Nav robot vacuum

This Memorial Day deal sucks… in a good way. The Dyson 360 Vis Nav may have the best suction of

23 mag 2025, 18:40:22 | Engadget
OnlyFans is in talks to sell for $8 billion

OnlyFans is on the selling block,

23 mag 2025, 18:40:21 | Engadget