CERT-In issued a high-severity warning regarding serious vulnerabilities found in multiple Apple products, such as iPhones and Apple Watches. These vulnerabilities could potentially allow hackers to execute arbitrary code, gain escalated privileges, or bypass security measures on the impacted devices.

Credit: AFP via Getty Images

Understanding the Risks

The vulnerabilities come from problems in certificate validation within key components like Security, Kernel, and WebKit in Apple products. Specifically, the flaws impact the Safari browser and other browsers using WebKit. These vulnerabilities enable attackers to bypass security protocols, gain elevated access rights, and execute arbitrary code on targeted systems.

The WebKit vulnerability poses a significant risk as it could enable attackers to take control of Apple devices, potentially accessing personal data, files, and even installing malware. This threat arises when users are lured to malicious websites or open harmful attachments. The security concerns extend to various Apple software versions, including macOS Monterey, macOS Ventura, watchOS, iOS, iPadOS, and Safari.

To reduce the risks associated with these vulnerabilities, users are strongly advised by the national authority to promptly update their Apple devices to the latest available versions. Apple has released updates to address these vulnerabilities, which can be obtained from the official website, cert-in.org.in.

CERT-In is a central organization operating under the Ministry of Electronics and Information Technology, Government of India.

Here’s the list of the affected software:

  • Apple macOS Monterey versions prior to 12.7
  • Apple macOS Ventura versions prior to 13.6
  • Apple watchOS versions prior to 9.6.3
  • Apple watchOS versions prior to 10.0.1
  • Apple iOS versions prior to 16.7 and iPadOS versions prior to 16.7
  • Apple iOS versions prior to 17.0.1 and iPadOS versions prior to 17.0.1
  • Apple Safari versions prior to 16.6.1

RELATED:

(Source, Via)