Apple users told to update iOS and macOS immediately to stop this security threat

app security
(Image credit: Shutterstock.com)

Users of Apple devices have been told to update and patch their iOS and macOS devices following the discovery of another significant security threa,

Apple has patched yet another zero-day that existed in both its mobile (iOS) and desktop (macOS) operating systems, and has actively been exploited in the wild.

The bug could be exploited to execute arbitrary code with kernel privileges on vulnerable devices, warns Apple’s advisory. Reported by an anonymous researcher, the vulnerability affected virtually all Apple-ware including Macs, iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad Mini 4 and later, and iPod touch (7th generation).

Tracked as CVE-2021-30807, Apple describes the vulnerability as a memory corruption issue in the IOMobileFramebuffer kernel extension.

Active exploitation

Apple acknowledged reports that the bug “may have been actively exploited,” but didn’t share any further details about the exploitation.

Meanwhile, The Record has spotted a proof-of-concept exploit posted by a security researcher that takes advantage of the CVE-2021-30807 vulnerability, while another has published a detailed analysis claiming to have found the bug independently. 

Notably, CVE-2021-30807 is the 13th zero-day vulnerability that Apple has had to patch this year alone. While a majority of the earlier zero-days impacted iOS and iPadOS, a couple also troubled macOS users as well. 

In any case, Apple urges its users to update to the updated iOS 14.7.1, iPadOS 14.7.1, and macOS Big Sur 11.5.1 versions it has released to address the CVE-2021-30807 vulnerability.

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow