Last week, Apple released an important update for its devices, patching (opens in a new tab) two major security holes. However, it is now suggested that not all macOS versions received the fix.
While macOS Monterey users are now protected from the vulnerability with the latest update, users running Big Sur and Catalina are still exposed, a security researcher claims.
Talking to analysts, The Register found that Big Sur users were more vulnerable than those using Catalina. According to Joshua Long, Principal Security Analyst at Intego, Catalina lacks the AppleAVD component used to decode audio and video and is therefore not affected by one of the vulnerabilities. However, another flaw affects both versions.
So far, Apple has remained silent on the matter. TechRadar Pro has reached out to a representative for the company but received no immediate response.
macOS Vulnerability
macOS Catalina was first released in October 2019 and should end its life cycle in November this year, while macOS Big Sur will hit virtual shelves a year later in November 2020, with support until November 2023.
However, Long said that at least one-third of all Macs in use today run on one of the vulnerable operating systems.
The first vulnerability is an out-of-bounds write vulnerability in the Intel graphics driver that allows applications to read kernel memory, while the second is an out-of-bounds read issue in the AppleAVD media decoder that allows applications to execute arbitrary code with kernel privileges.
Apple said the flaws may have been widely exploited, most likely for identity theft, malware distribution and other malicious activities, urging users to update their operating systems to the latest version as soon as possible.
All iPhone models starting with iPhone 6 and various iPad and iPod Touch models are affected, except for the Apple Mac.
>>>>>>>>>>>>>>Apple battery

Comments
Post a Comment