Apple closes three zero days in iOS
Apple has released an update for iOS that closes three zero days. The holes in the kernel and WebKit were actively exploited, according to the company. The company did not provide details about that specific attack.
These are holes in iOS 14.3 and iPadOS 14.3 that have been updated to version 14.4. There were three bugs in the operating system, Apple writes in the patch notes. The bugs were raised by anonymous security researchers. One of the leaks is in the iOS kernel. CVE-2021-1782 is a privilege escalation bug caused by a race condition that could be loaded by an infected application
In addition, two other vulnerabilities have been discovered in WebKit. The Safari browser, among other things, uses this. CVE-2021-1870 and CVE-2021-1871 are logic issues that were exploited by visiting an infected website. This allowed code to be executed on the device. Apple does not provide further details about the vulnerabilities or the attacks in which they would be used. Due to the nature of the leaks, it is possible that they are carried out in combination with each other.