Apple releases emergency iOS and macOS updates to patch nasty security hole

MacBook Air
(Image credit: Apple)

Apple has published a pair of “important” updates for iOS and macOS that address a nasty security issue that could put devices at risk.

iOS 14.4.1 and macOS 11.2.3 contain fixes for a vulnerability in WebKit, the engine that props up Safari and other iOS browsers. Identified by researchers at Google and Microsoft, the bug could be exploited by hackers to execute code on target devices.

Given the potential for abuse, Apple has recommended owners of its smartphones, tablets and PCs install the updates immediately.

iOS and macOS security update

Although Apple provided little information in the release notes, which simply state that the new versions “provide important security updates and are recommended for all users”, the company’s website sheds a little more light.

The bug is described as a “memory corruption issue” that has been “addressed with improved validation”. If the problem is not addressed, says Apple, cybercriminals could use “maliciously crafted web content” to perform remote code execution on affected devices.

The vulnerability (CVE-2021-1844) has been handed a high severity rating of 7.7/10, by the Common Vulnerability Scoring System (CVSS).

The iOS update is available for iPhone 6 models and newer, iPad Air 2 and newer, iPad mini 4 and newer, and iPod touch (7th generation). And the Mac update is available for macOS Big Sur.

If the update has not been deployed automatically, iOS users can perform a manual install by navigating to Settings > General and then selecting Software Update.

Mac owners, meanwhile, will need to find their way to the System Preferences panel via the Apple menu, and then click Software Update.

Via 9to5Mac

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Latest in News
A phone showing a ChatGPT app error message
ChatGPT is down for many – here's what's going on
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping