Apple releases emergency iOS and macOS updates to patch nasty security hole

MacBook Air
(Image credit: Apple)

Apple has published a pair of “important” updates for iOS and macOS that address a nasty security issue that could put devices at risk.

iOS 14.4.1 and macOS 11.2.3 contain fixes for a vulnerability in WebKit, the engine that props up Safari and other iOS browsers. Identified by researchers at Google and Microsoft, the bug could be exploited by hackers to execute code on target devices.

Given the potential for abuse, Apple has recommended owners of its smartphones, tablets and PCs install the updates immediately.

iOS and macOS security update

Although Apple provided little information in the release notes, which simply state that the new versions “provide important security updates and are recommended for all users”, the company’s website sheds a little more light.

The bug is described as a “memory corruption issue” that has been “addressed with improved validation”. If the problem is not addressed, says Apple, cybercriminals could use “maliciously crafted web content” to perform remote code execution on affected devices.

The vulnerability (CVE-2021-1844) has been handed a high severity rating of 7.7/10, by the Common Vulnerability Scoring System (CVSS).

The iOS update is available for iPhone 6 models and newer, iPad Air 2 and newer, iPad mini 4 and newer, and iPod touch (7th generation). And the Mac update is available for macOS Big Sur.

If the update has not been deployed automatically, iOS users can perform a manual install by navigating to Settings > General and then selecting Software Update.

Mac owners, meanwhile, will need to find their way to the System Preferences panel via the Apple menu, and then click Software Update.

Via 9to5Mac

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
The Apple logo is seen with the iOS 18 operating system logo in the background on a mobile device
Apple fixes Passwords app security bug with new 18.2 update
Someone checking their credit card details online.
Apple forced to patch iOS and macOS security flaw that could have leaked your private info
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day