Apple has recently rolled out software updates for all of its products in order to address two security flaws. The company stated that these vulnerabilities could potentially have been exploited to compromise the security of customers using their mobile operating system, iOS.
According to security reports on its official site, Apple has addressed the two zero-day vulnerabilities that were potentially utilized in a highly sophisticated attack aimed at specific individuals using iOS.
The bugs are considered zero days because they were exploited before being discovered by Apple.
The individuals responsible for the attacks and the number of Apple customers affected are still unknown, and it is uncertain if any customers were successfully compromised. Despite an inquiry sent to Apple, it is yet to be responded to.
According to Apple, one of the two bugs was found by security researchers at Google’s Threat Analysis Group. This suggests that a nation state or government agency may be responsible for the attacks on Apple customers. Certain government-backed cyberattacks are known to utilize remotely deployed spyware and other phone-unlocking tools.
TechCrunch reached out to Google via comment, but a spokesperson did not provide an immediate response.
According to Apple, 2 bugs have been found in their Core Audio component, the system-level component that Apple uses across its various products to allow developers to interact with device audio. The company also stated that this particular bug could be taken advantage of by manipulating an audio stream within a corrupted media file, potentially resulting in the execution of malicious code on the device.
Apple claimed credit for discovering another bug that enables attackers to bypass pointer authentication. Pointer authentication is a security feature used by Apple in its software to prevent malicious code from being injected into a device’s memory.
Apple has rolled out an update for macOS Sequoia, bringing it to version 15.4.1. In addition, iPhone and iPad users can now download iOS 18.4.1, which fixes security issues. Not only that, but Apple has also ensured the safety of its Apple TV and Vision Pro mixed-reality headset with the same updates.