CERT-In Detects Threats With High Severity in iPhone, iPad, Mac, ChromeOS and Firefox Browser

These vulnerabilities can be fixed by installing software updates.

Advertisement
By Sourabh Kulesh | Updated: 2 August 2022 17:33 IST
Highlights
  • Criminals can execute arbitrary code
  • Attackers can cause DoS attacks on machines
  • They can also access sensitive information

Vulnerabilities can be used to bypass security restrictions

Photo Credit: Reuters

The Indian Computer Emergency Response Team (CERT-In) appointed by the Ministry of Electronics and Information Technology has found multiple vulnerabilities of high severity in iOS, iPadOS, and macOS by Apple as well as Google' ChromeOS and Mozilla' Firefox Internet browser. iOS is an operating system for iPhone models, iPadOS runs on iPad models, and macOS powers the Mac machines. As per the nodal agency, these vulnerabilities can be used to bypass security restrictions and cause denial-of-service (DoS) attacks rendering the devices unusable.

Mac machines running on macOS Catalina with security update prior to 2022-005, macOS Big Sur versions prior to 11.6.8, and macOS Monterey versions prior to 12.5 are at risk, as per CERT-In. The vulnerabilities in macOS versions as well as iOS and iPadOS could be exploited by a remote attacker by persuading a victim to visit a malicious website. The cybercriminal can execute arbitrary code, bypass security restrictions, and cause DoS conditions on the targeted system.

The macOS vulnerabilities exist due to out-of-bounds read in AppleScript, SMB and Kernel, out-of-bounds write in Audio, ICU, PS Normalizer, GU Drivers, SMB and WebKit. Authorisation issues have been found in AppleMobileFileIntegrity; information disclosure in the Calendar and iCloud Photo Library.

Advertisement

Similar vulnerabilities have been found in iOS and iPadOS versions prior to 15.6. The macOS vulnerabilities exist due to out-of-bounds write in Audio, ICU, GPU Drivers, and WebKit, out-of-bounds read in ImageIO and Kernel, authorisation issues have been found in AppleMobileFileIntegrity; information disclosure in the Calendar and iCloud Photo Library, among others.

Advertisement

In case of Mozilla Firefox, versions prior to 103, ESR versions prior to 102.1 and 91.12 have been found vulnerable. The vulnerabilities exist due to Memory safety bugs within the browser engine, preload cache bypasses subresource integrity, leak of cross-site resource redirecting information while using the Performance API, among others. These loopholes may provide an attacker access to sensitive information on the targeted system.

The vulnerabilities in Google ChromeOS pose a pretty similar threat as Firefox. The vulnerabilities exist in Google ChromeOS LTS channel versions prior to 96.0.4664.215 due to out-of-bounds read in the compositing component, incorrect implementation in Extension API, use-after-free error within the Blink XSLT component, among others.

Advertisement

CERT-In says these vulnerabilities can be fixed by installing software updates. Users of these operating systems and Mozilla Firefox are advised to install the software patches as soon as they can.


Is Pixel 6a the best camera phone under Rs. 50,000? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Price: US vs UAE vs India - Where Is It Cheapest to Buy?
  2. Pixel 9 for Under Rs. 36,000? Flipkart's Big Billion Days Deal Revealed
  3. Who Is Abidur Chowdhury, the Designer Who Introduced the iPhone Air?
  4. All the Key Differences Between iPhone 17 and iPhone 17 Pro
  5. Apple Launches iPhone 17 Pro, 17 Pro Max With These Massive Upgrades
  6. Apple Watch Series 11, Ultra 3, SE Launched With These Health Features
  7. Apple Discontinues These iPhone Models After iPhone 17 Launch
  8. Apple Launches iPhone 17 at 'Awe Dropping' Event With These Upgrades
  9. iPhone 17 Pro: 5 Best New Features You Need to Know About
  10. Google Launches a Cheaper AI Subscription Plan With These Benefits
  1. Apple Introduces Memory Integrity Enforcement to Protect iPhone 17 Series from Sophisticated Malware Attacks
  2. Apple's iOS 26 RC Update Adds Icon Tinting Feature to Match Your iPhone or MagSafe Case
  3. Nothing OS 4.0 With Android 16 Confirmed to Launch Soon, Design Teased Ahead of Rollout
  4. Google AI Plus Subscription Plan Launched With Affordable Pricing, Access to Veo 3 Fast
  5. GTA 6 Delay Led to Celebrations at Sucker Punch, Ghost of Yotei Director Says
  6. OnePlus 15 Tipped to Launch in Three Colour Options Ahead of Anticipated Debut
  7. Apple's AirPods Pro 3 Has a Live Translation Feature That Will Come to the AirPods Pro 2, AirPods 4
  8. iPhone 17 vs iPhone 16: Here Is a Quick Comparison of Advertised Video Playback Times
  9. The New AirPods Lineup for 2025: AirPods Pro 3 Arrives, Pro 2 Departs
  10. Bitcoin Price Drops to $111,700 as Traders Await CPI, ECB Signals
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.