Aktívan kihasznált, iOS-t, iPadOS-t, macOS-t érintő sebezhetőségre adott ki az Apple soron kívüli javítást

Címkék
Tracked as CVE-2022-22675, the issue has been described as an out-of-bounds write vulnerability in an audio and video decoding component called AppleAVD that could allow an application to execute arbitrary code with kernel privileges.

Apple said the defect was resolved with improved bounds checking, adding it's aware that "this issue may have been actively exploited."

Részletek itt.

Hozzászólások

an out-of-bounds write vulnerability in an audio and video decoding component called AppleAVD that could allow an application to execute arbitrary code with kernel privileges.

Magyarul, egy megpatkolt videó, podcast lejátszása kernel jogokhoz juttathatja a támadót.

Apple iOS up to 12.0.1 AppleAVD memory corruption

Deja vu.

PS: ha nem jön a frissítés automatikusan, tessék nyomkodni! ;)

trey @ gépház