Exploitable WebKit flaw still present in iOS and macOS despite available fix
Apple has not yet patched a WebKit vulnerability present in iOS and macOS despite a fix for the flaw being available for weeks.
Stay updated with breaking news from Tim Becker. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Apple has not yet patched a WebKit vulnerability present in iOS and macOS despite a fix for the flaw being available for weeks.
Apple has not yet patched a WebKit vulnerability present in iOS and macOS despite a fix for the flaw being available for weeks. Credit: WebKit
What you need to know A WebKit exploit exists that could allow the execution of malicious code on a Mac, iPhone, and iPad. Researchers told Apple how to fix the issue three weeks ago, but it still hasn't been done. A security exploit that could allow malicious code to be run on Macs, iPhones, and iPads hasn't been fixed despite someone telling Apple how to do so three weeks ago. The flaw relates to WebKit across macOS, iOS, and iPadOS. Webkit is what powers Safari and a number of similar web browsers and the bug appears to be related to AudioWorklet which manages audio output from web pages. ...
Failure to check the object type provides an opportunity for an attacker to create a type confusion error capable of crashing Safari. Developing a more serious exploit that enables arbitrary code execution would require additional work to create exploit primitives that bypass WebKit defenses like Pointer Authentication Codes (cryptographic signatures for pointers on Arm-compatible devices). Becker nonetheless suggests this malware defense can be overcome by attackers, pointing to recent Project Zero research. "This exploit is only the first stage in compromising a user's device," said Becker ...
The Republican-controlled Senate and Assembly both adjourn sessions without debate or votes.