CERT-In Detects Threats With High Severity In iPhone, iPad, Mac, ChromeOS and Firefox Browser

SHARE:

The Indian Computer Emergency Response Team or CERT-In, appointed by the Ministry of Electronics and Information Technology, has found sever...

The Indian Computer Emergency Response Team or CERT-In, appointed by the Ministry of Electronics and Information Technology, has found several highly severe vulnerabilities in iOS, iPadOS, and macOS. Additionally, they've also found some vulnerabilities in Google's ChromeOS and Mozilla's Firefox browser as well. According to the agency, these vulnerabilities can be used to bypass security restrictions and cause DoS or denial-of-service attacks on users, rendering their devices unusable.

Machines running macOS Catalina with a security patch prior to 2022-005, macOS Big Sur versions prior to 11.6.8, and macOS Monterey versions prior to 12.5 are at risk. These vulnerabilities which are present in macOS as well as iOS and iPadOS can be exploited by attackers remotely; all they need to do is persuade victims to visit a malicious website. The attacker can then execute an arbitrary code which would bypass security restrictions and cause the DoS attack on the device.

The vulnerabilities in macOS exist due to out-of-bounds read in AppleScript, SMB, and Kernel, out-of-bounds write in Audio, ICU, PS Normalizer, GU Drivers, SMB and WebKit. In addition to that, authorisation issues were found in AppleMobileFileIntegrity; information disclosure in the Calendar and iCloud Photo Library.

Similar vulnerabilities have been found in iPadOS and iOS versions prior to 15.6 as well.

As for Mozilla Firefox, versions older than 103, ESR versions older than 102.1 and 91.12 have been found to have security flaws. These flaws exist due to Memory safety bugs present in the browser engine, preload cache bypasses subresource integrity, and leak of cross-site resource redirecting information while using the Performance API, to name a few. Using these loopholes, attackers can gain access to sensitive information on targeted machines.

Google ChromeOS suffers from similar vulnerabilities to Firefox. They exist in Google ChromeOS LTS channel versions prior to 96.0.4664.215 due to out-of-bounds read in the compositing component, incorrect implementation in Extension API, and use-after-free error within the Blink XSLT component, to name a few.

According to CERT-In, these vulnerabilities can be fixed by installing software updates, and users of these operating systems and browsers should install the latest security updates as soon as they can.



from Internet News https://ift.tt/NE58wjK

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: CERT-In Detects Threats With High Severity In iPhone, iPad, Mac, ChromeOS and Firefox Browser
CERT-In Detects Threats With High Severity In iPhone, iPad, Mac, ChromeOS and Firefox Browser
https://i.ytimg.com/vi/1x8dcqO2RY0/hqdefault.jpg
https://i.ytimg.com/vi/1x8dcqO2RY0/default.jpg
Genius Baba
https://geniusbabaa.blogspot.com/2022/08/cert-in-detects-threats-with-high.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2022/08/cert-in-detects-threats-with-high.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy