Skip to content
The Code Studio

Responsive Website Design/Development Studio based in Mangalore

The Code Studio

Responsive Website Design/Development Studio based in Mangalore

CERT-In Detects Threats With High Severity in iPhone, iPad, Mac, ChromeOS and Firefox Browser

Ravindra, August 2, 2022October 26, 2023

The Ministry of Electronics and Information Technology’s Indian Computer Emergency Response Team (CERT-In) has identified several high-severity vulnerabilities in Apple’s iOS, iPadOS, and macOS, along with Google’s ChromeOS and Mozilla’s Firefox internet browser. iOS is utilized on iPhone models, iPadOS on iPads, and macOS on Mac machines. According to CERT-In, these vulnerabilities possess the potential to circumvent security measures, leading to denial-of-service (DoS) attacks that render the affected devices inoperable.

Machines running macOS Catalina with security updates before 2022-005, macOS Big Sur versions prior to 11.6.8, and macOS Monterey versions before 12.5 are particularly susceptible, as indicated by CERT-In. Exploiting these vulnerabilities involves convincing a user to visit a malicious website, allowing a remote attacker to execute arbitrary code, bypass security protocols, and induce DoS conditions on the targeted system.

The macOS vulnerabilities stem from out-of-bounds read in AppleScript, SMB, and Kernel, as well as out-of-bounds write in Audio, ICU, PS Normalizer, GU Drivers, SMB, and WebKit. Authorization issues were identified in AppleMobileFileIntegrity, and information disclosure in the Calendar and iCloud Photo Library.

Similar vulnerabilities affect iOS and iPadOS versions before 15.6, involving out-of-bounds write in Audio, ICU, GPU Drivers, and WebKit, out-of-bounds read in ImageIO and Kernel, and authorization issues in AppleMobileFileIntegrity, among others.

Mozilla Firefox versions before 103, ESR versions before 102.1, and 91.12 are susceptible to memory safety bugs within the browser engine, preload cache bypasses subresource integrity, and the leakage of cross-site resource redirecting information when using the Performance API.

Google ChromeOS, in LTS channel versions before 96.0.4664.215, faces vulnerabilities such as out-of-bounds read in the compositing component, incorrect implementation in Extension API, and a use-after-free error within the Blink XSLT component.

CERT-In advises users to mitigate these vulnerabilities by promptly installing software updates for the respective operating systems and Mozilla Firefox.

web development news

Post navigation

Previous post
Next post

Related Posts

web development news

iCloud Passwords for Windows Gets 2FA Code Generator Support: Report

July 26, 2022October 26, 2023

Apple has reportedly enhanced its iCloud for Windows client by introducing support for a two-factor authentication (2FA) code generator. This functionality is accessible through the iCloud Passwords app, allowing users to utilize passwords stored in iCloud Keychain on their Windows PCs. The 2FA codes offer an extra layer of security…

Read More
web development news

Revolutionizing the Game: Exploring New Design Solutions in Sports

January 16, 2024February 16, 2024

In the ever-evolving world of sports, innovation is the name of the game.
Elevate your sports betting journey with the range of 1xbet apps, offering seamless access to a variety of markets and competitive odds, customized for different devices.

Read More
web development news

LastPass Faces Data Breach; Company Says No Passwords Taken: Details

August 26, 2022October 26, 2023

Recently, LastPass, a widely used password manager with over 33 million users, fell victim to a hack where an unauthorized party gained access to the company’s source code and proprietary information by exploiting the developer environment. LastPass has assured users that no passwords were believed to have been compromised in…

Read More

Recent Posts

  • Revolutionizing the Game: Exploring New Design Solutions in Sports
  • LastPass Faces Data Breach; Company Says No Passwords Taken: Details
  • Signal Fears Phishing Attackers May Have Accessed Phone Numbers of 1,900 Users
  • CERT-In Detects Threats With High Severity in iPhone, iPad, Mac, ChromeOS and Firefox Browser
  • iCloud Passwords for Windows Gets 2FA Code Generator Support: Report
©2026 The Code Studio | WordPress Theme by SuperbThemes