iOS 18.4.1 patches two iPhone security flaws used in 'extremely sophisticated' attacks

On Wednesday, Apple pushed updates to most of its platforms: iOS 18.4.1, iPadOS 18.4.1, macOS 15.4.1, tvOS 18.4.1 and visionOS 2.4.1. They contain two security fixes for flaws that may have been used in real-world attacks, so it's wise to update your devices without too much delay.

Apple is aware of a report that both security issues "may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

One patched bug is in Apple's audio framework, CoreAudio. This memory corruption issue allowed malicious media files to execute code when processed as audio streams. The other relates to the Remote Participant Audio Control (RPAC) framework, which lets communications apps manage audio streams. That flaw allowed an attacker with arbitrary read / write capabilities to bypass Pointer Authentication (a security feature in Apple's processors).

Apple "strongly advises" all users to update their devices.

This article originally appeared on Engadget at https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss https://www.engadget.com/mobile/smartphones/ios-1841-patches-two-iphone-security-flaws-used-in-extremely-sophisticated-attacks-194922877.html?src=rss
Creată 17d | 16 apr. 2025, 20:50:11


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

Doctor Who ‘Lucky Day’ review: Pete, I owe you an apology

Spoilers for “Lucky Day.”

When the writers for this season of Doctor Who were announced, one name in the roster put me instantly on edge. Pete McTighe may

3 mai 2025, 21:10:20 | Engadget
How to watch NVIDIA CEO Jensen Huang deliver the Computex 2025 keynote

Computex 2025 is approaching, and it’s sure to bring a ton of announcements about the latest chips, laptops, gaming devices and more from leading brands. The event in Taipei will kick off on Monday

3 mai 2025, 21:10:19 | Engadget
Kids under 13 will soon get supervised access to Google Gemini

Google Gemini is adding nannying to its chatbot skillset. According to a New

3 mai 2025, 18:40:16 | Engadget
Half-Life 3 is reportedly playable in its entirety and could be announced this year

Cue a new batch of “Half-Life 3 confirmed” memes. The latest rumor surrounding Valve’s long-awaited next installment in the Half-Life series claims that the game is currently “pla

3 mai 2025, 18:40:15 | Engadget
The Louvre will stop renting out Nintendo 3DS audio guides in September

In a few months, you'll no longer be able to rent a Nintendo 3DS to guide you around the Louvre and tell y

3 mai 2025, 16:30:04 | Engadget
Bandai releases Tamagotchi Paradise comic for Free Comic Book Day, and it may hint at the next device

It’s the first Saturday of May, which means Free Comic Book Day is here, and this year, even

3 mai 2025, 16:30:03 | Engadget