Apple fixes two zero days in iOS 17, iPadOS 17 and macOS

Spread the love

Apple on Thursday released a patch for iOS 17.1.2, iPadOS 17.1.2 and macOS Sonoma 14.1.2 that fixes two vulnerabilities. These are in the WebKit browser engine. This concerns an out-of-bounds read bug and a memory corruption bug.

In the patch notes stands that the vulnerabilities have been assigned the registrations CVE-2023-42916 and CVE-2023-42917. Both zero-days were discovered and reported by Clément Lecigne of Google’s Threat Analysis Group.

The zerodays were found in WebKit. Apple says of CVE-2023-42916 that it “may disclose sensitive information when processing web content.” Regarding CVE-2023-42917, Apple writes that “processing web content may lead to arbitrary code execution.” The company says it is aware of a report about the possible misuse of zero days in iOS versions prior to version 16.7.1.

Update: Added macOS patch information and link.

You might also like
Exit mobile version