iOS 15.3 - nuovo aggiornamento per migliorare la sicurezza degli iPhone
27 Gennaio 2022 | Max Capitosti
APPLE CERCA Nelle ultime ore è iniziata la distribuzione della versione definitiva di iOS 15.3, al termine della fase di test che si è protratta all'incirca per un mese e mezzo. Il rilascio avviene a due settimane di distanza dal precedente aggiornamento iOS 15.2.1 ed include il firmware iPadOS 15.3 dedicato agli iPad.
Il change-log con l'elenco delle migliorie è piuttosto corposo, ma riguarda quasi esclusivamente la risoluzione dei bug scoperti di recente che pregiudicavano la sicurezza dei dispositivi durante la navigazione web. Per questo motivo Apple consiglia alla clientela di procedere all'aggiornamento appena possibile.
FACEBOOKSEGUICI SU
TELEGRAMNOTIZIE CORRELATE
Il change-log con l'elenco delle migliorie è piuttosto corposo, ma riguarda quasi esclusivamente la risoluzione dei bug scoperti di recente che pregiudicavano la sicurezza dei dispositivi durante la navigazione web. Per questo motivo Apple consiglia alla clientela di procedere all'aggiornamento appena possibile.
iOS 15.3 and iPadOS 15.3SEGUICI SU
ColorSync
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: Processing a maliciously crafted file may lead to arbitrary code execution
Description: A memory corruption issue was addressed with improved validation.
CVE-2022-22584: Mickey Jin (@patch1t) of Trend Micro
Crash Reporter
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A malicious application may be able to gain root privileges
Description: A logic issue was addressed with improved validation.
CVE-2022-22578: an anonymous researcher
iCloud
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: An application may be able to access a user's files
Description: An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization.
CVE-2022-22585: Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab (https://xlab.tencent.com)
IOMobileFrameBuffer
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Description: A memory corruption issue was addressed with improved input validation.
CVE-2022-22587: an anonymous researcher, Meysam Firouzi (@R00tkitSMM) of MBition - Mercedes-Benz Innovation Lab, Siddharth Aeri (@b1n4r1b01)
Kernel
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A malicious application may be able to execute arbitrary code with kernel privileges
Description: A buffer overflow issue was addressed with improved memory handling.
CVE-2022-22593: Peter Nguyễn Vũ Hoàng of STAR Labs
Model I/O
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: Processing a maliciously crafted STL file may lead to unexpected application termination or arbitrary code execution
Description: An information disclosure issue was addressed with improved state management.
CVE-2022-22579: Mickey Jin (@patch1t) of Trend Micro
WebKit
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: Processing a maliciously crafted mail message may lead to running arbitrary javascript
Description: A validation issue was addressed with improved input sanitization.
CVE-2022-22589: Heige of KnownSec 404 Team (knownsec.com) and Bo Qu of Palo Alto Networks (paloaltonetworks.com)
WebKit
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: Processing maliciously crafted web content may lead to arbitrary code execution
Description: A use after free issue was addressed with improved memory management.
CVE-2022-22590: Toan Pham from Team Orca of Sea Security (security.sea.com)
WebKit
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced
Description: A logic issue was addressed with improved state management.
CVE-2022-22592: Prakash (@1lastBr3ath)
WebKit Storage
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A website may be able to track sensitive user information
Description: A cross-origin issue in the IndexDB API was addressed with improved input validation.
CVE-2022-22594: Martin Bajanik of FingerprintJS
FACEBOOKSEGUICI SU
TELEGRAMNOTIZIE CORRELATE
ULTIME NOTIZIE
- Xiaomi Mix Flip - in arrivo a fine mese, in anteprima nuove immaginiRealme GT6 - una dotazione differente per la versione per il mercato della CinaRedmi 13 5G - nuovo smartphone con Snapdragon 4 Gen 2 e fotocamera da 108MPOppo lancia i nuovi Reno 12 F 5G e Reno 12 FS 5G in ItaliaOnePlus svela nuovi dettagli sulle novità in arrivo il 16 luglioVodafone - insieme a Meta per ottimizzare l'efficienza della reteNothing CMF Phone 1 - lo smartphone 5G economico con retro personalizzabileOnePlus svela la gamma di prodotti per il Summer Launch Event del 16 luglioRealme C61 - ufficiale il nuovo entry-level con resistenza a polvere e acqua IP54Vivo Y28s 5G - ufficiale il nuovo smartphone di fascia mediaRealme 12 4G - chip Snapdragon 685 e schermo OLED per la nuova variante senza 5GApple estende il software di diagnostica Self Service Repair in Europa