LOGO

Apple Zero-Day Exploit Fixed - Urgent Security Update

January 28, 2025
Apple Zero-Day Exploit Fixed - Urgent Security Update

Apple Rolls Out Operating System Updates with Security Fixes and Apple Intelligence

On Monday, Apple initiated the distribution of its newest software updates for the iPhone, iPad, and Mac ecosystems. A key component of these updates is the default activation of Apple Intelligence on compatible devices.

Critical Security Patches Included

Alongside the introduction of Apple Intelligence, this software release incorporates several security enhancements. These include remediation for a zero-day vulnerability that was potentially being leveraged by malicious actors.

Devices operating on software versions prior to iOS 17.2, which became available in December 2023, were susceptible to exploitation. This indicates that users with older iPhone models were at risk.

Core Media Vulnerability Addressed

The identified vulnerability resided within Core Media, the foundational media processing component utilized across Apple’s diverse product range.

Consequently, the fix has been implemented across the entire Apple lineup, encompassing iPhones, iPads, Macs, Apple TVs, Apple Watches, and the innovative Vision Pro headset.

Successful exploitation of the memory corruption flaw could have granted attackers elevated system privileges, potentially leading to unauthorized access to sensitive device data.

Bug Discovery and Attribution

Apple did not publicly acknowledge any specific researcher for the discovery of this particular vulnerability, deviating from its usual practice.

When queried for further information regarding the exploitation details and targeted individuals, an Apple representative did not provide an immediate response.

First Exploited iOS Bug of 2024

This represents the first instance of a publicly known iOS vulnerability being actively exploited this year.

According to TechCrunch’s ongoing record, Apple has addressed at least seven vulnerabilities that exhibited evidence of active exploitation throughout 2024.

  • Apple Intelligence is now enabled by default on newer devices.
  • A zero-day vulnerability was patched, impacting devices running software older than iOS 17.2.
  • The vulnerability was located in Core Media and affected all Apple platforms.
#apple#zero-day#vulnerability#security#iphone#ipad