December was a busy month for updates as corporations together with Apple and Google rushed to get patches out to repair critical flaws of their merchandise earlier than the vacation break.
Enterprise software program giants additionally issued their fair proportion of patches, with Atlassian and SAP squashing a number of important bugs throughout December.
Right here’s what it is advisable to know concerning the vital updates you might need missed in the course of the month.
Apple iOS
In mid-December, Apple launched iOS 17.2, a serious level improve containing options such because the Journal app, in addition to 12 safety patches. Among the many flaws fixed in iOS 17.2 is CVE-2023-42890, a problem within the WebKit browser engine that might enable an attacker to execute code.
One other flaw within the iPhone’s Kernel, tracked as CVE-2023-4291, might see an app escape of its safe sandbox, Apple wrote on its support page. In the meantime, two vulnerabilities in ImageIO, CVE-2023-42898 and CVE-2023-42899, might result in code execution.
The iOS 17.2 replace additionally put a mechanism in place to forestall a Bluetooth assault utilizing a penetration testing gadget known as Flipper Zero, based on exams by ZDNET and 9to5Mac. The annoying denial of service cyber-assault might trigger a flurry of pop ups to look on an iPhone and ultimately lock up the gadget.
Apple additionally launched iOS 16.7.3, Safari 17.2, macOS Sonoma 14.2, macOS Ventura 13.6.3, macOS Monterey 12.7.2, tvOS 17.2 and watchOS 10.2.
Only one week after releasing iOS 17.2, Apple issued iOS 17.2.1 and iOS 16.7.4 for older units, alongside macOS Sonoma 14.2.1. The shock iPhone replace accommodates unspecified bug and safety fixes, whereas the macOS patch fixes a single flaw tracked as CVE-2023-42940.
Google Android
The Google Android December Security Bulletin was a hefty one, fixing practically 100 safety points. The replace consists of patches for 2 important points within the Framework, essentially the most extreme of which might result in distant escalation of privilege with no further privileges wanted. Consumer interplay just isn’t wanted for exploitation, Google mentioned.
CVE-2023-40088 is a important flaw within the System that might result in distant code execution, whereas CVE-2023-40078 is an elevation of privilege bug rated as having a excessive influence.
Google has additionally issued an update for its good gadget WearOS platform, fixing CVE-2023-40094, an elevation of privilege flaw. The Pixel Safety Bulletin has not been posted on the time of writing.
Google Chrome
Google ended a bumper December of updates in fashion with an emergency fix for its Chrome browser. The eighth zero-day vulnerability impacting Chrome in 2024, CVE-2023-7024 is a heap buffer overflow concern within the open supply WebRTC part. Google is “conscious that an exploit for CVE-2023-7024 exists within the wild,” the browser maker mentioned in an advisory.
It wasn’t the primary repair launched by Google in December. The software program large additionally issued a Chrome patch mid-month to repair 9 safety points. Of the failings reported by exterior researchers, 5 are rated as having a excessive severity, together with CVE-2023-6702, a kind confusion flaw in V8, and 4 use-after-free bugs.
Thank you for being a valued member of the Nirantara family! We appreciate your continued support and trust in our apps.
- Nirantara Social - Stay connected with friends and loved ones. Download now: Nirantara Social
- Nirantara News - Get the latest news and updates on the go. Install the Nirantara News app: Nirantara News
- Nirantara Fashion - Discover the latest fashion trends and styles. Get the Nirantara Fashion app: Nirantara Fashion
- Nirantara TechBuzz - Stay up-to-date with the latest technology trends and news. Install the Nirantara TechBuzz app: Nirantara Fashion
- InfiniteTravelDeals24 - Find incredible travel deals and discounts. Install the InfiniteTravelDeals24 app: InfiniteTravelDeals24
If you haven't already, we encourage you to download and experience these fantastic apps. Stay connected, informed, stylish, and explore amazing travel offers with the Nirantara family!
Source link