Apple releases emergency iOS and macOS updates to patch nasty security hole

MacBook Air
(Image credit: Apple)

Apple has published a pair of “important” updates for iOS and macOS that address a nasty security issue that could put devices at risk.

iOS 14.4.1 and macOS 11.2.3 contain fixes for a vulnerability in WebKit, the engine that props up Safari and other iOS browsers. Identified by researchers at Google and Microsoft, the bug could be exploited by hackers to execute code on target devices.

Given the potential for abuse, Apple has recommended owners of its smartphones, tablets and PCs install the updates immediately.

iOS and macOS security update

Although Apple provided little information in the release notes, which simply state that the new versions “provide important security updates and are recommended for all users”, the company’s website sheds a little more light.

The bug is described as a “memory corruption issue” that has been “addressed with improved validation”. If the problem is not addressed, says Apple, cybercriminals could use “maliciously crafted web content” to perform remote code execution on affected devices.

The vulnerability (CVE-2021-1844) has been handed a high severity rating of 7.7/10, by the Common Vulnerability Scoring System (CVSS).

The iOS update is available for iPhone 6 models and newer, iPad Air 2 and newer, iPad mini 4 and newer, and iPod touch (7th generation). And the Mac update is available for macOS Big Sur.

If the update has not been deployed automatically, iOS users can perform a manual install by navigating to Settings > General and then selecting Software Update.

Mac owners, meanwhile, will need to find their way to the System Preferences panel via the Apple menu, and then click Software Update.

Via 9to5Mac

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
The Apple logo is seen with the iOS 18 operating system logo in the background on a mobile device
Apple fixes Passwords app security bug with new 18.2 update
Someone checking their credit card details online.
Apple forced to patch iOS and macOS security flaw that could have leaked your private info
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in News
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
An Nvidia GeForce RTX 4060 on a table with its retail packaging
Nvidia RTX 5060 GPU spotted in Acer gaming PC, suggesting rumors of imminent launch are correct – and that it’ll run with only 8GB of video RAM
Indiana Jones talking to a friend in a university setting with a jaunty smile on his face
New leak claims Indiana Jones and the Great Circle PS5 release will come in April
A close up of the limited edition vinyl turntable wrist watch from AndoAndoAndo
This limited-edition timepiece turns the iconic Technics SL-1200 turntable into a watch, and I want one