Older macOS versions reportedly remain insecure after Apple chose only to patch Monterey

Apple
Apple takes a bite out of previous sales (Image credit: Future)

Last week, Apple released an important update for its devices, patching two major security flaws. However, it has now been suggested that not all macOS versions received the fix.

Although macOS Monterey users are now protected from the vulnerabilities with the latest update, those running Big Sur and Catalina remain exposed, a security researcher has claimed.

Speaking to analysts, The Register found that Big Sur users are in a more vulnerable position than those using Catalina. According to chief security analyst for Intego, Joshua Long, Catalina lacks the AppleAVD component for decoding audio and video and is therefore immune to one of the vulnerabilities. The other flaw, however, affects both versions.

So far, Apple has remained quiet on the matter. TechRadar Pro has reached out to the company’s representatives, but did not receive an immediate response.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

macOS vulnerabilities

macOS Catalina was first released in October 2019, and should hit end-of-life in November this year, while macOS Big Sur hit the virtual shelves a year later, in November 2020, and should be supported until November 2023. 

However, Long says that at least a third of Macs currently being used run on one of the vulnerable operating systems.

The first flaw is an out-of-bounds write vulnerability in the Intel Graphics Driver that allows apps to read kernel memory, while the second is an out-of-bounds read issue in the AppleAVD media decoder, allowing apps to execute arbitrary code with kernel privileges.

Apple says the flaws might have been exploited in the wild, most likely for identity theft, malware distribution, and other malicious activity, so users are urged to update their operating systems to the newest version as soon as possible.

In addition to Apple Macs, all iPhone models from the iPhone 6 onwards are affected, as well as a wide range of iPad and iPod Touch models.

Via The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Apple&#039;s new &quot;Share Item Location&quot; feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
A person in a wheelchair working at a computer.
Why betting on Mac security could put your organization at risk
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That&#039;s Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard