{"id":1180080,"date":"2023-09-07T18:47:27","date_gmt":"2023-09-07T22:47:27","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1180080"},"modified":"2023-09-07T18:47:27","modified_gmt":"2023-09-07T22:47:27","slug":"apple-patches-clickless-0-day-image-processing-vulnerability-in-ios-macos","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1180080","title":{"rendered":"Apple patches \u201cclickless\u201d 0-day image processing vulnerability in iOS, macOS"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/09\/iphone-14-hero-800x450-1.jpg\" alt=\"Apple patches &#x201C;clickless&#x201D; 0-day image processing vulnerability in iOS, macOS\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/02\/iphone-14-hero-scaled.jpg\" class=\"enlarge-link\" data-height=\"1440\" data-width=\"2560\">Enlarge<\/a> (credit: Apple)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>Apple has released security updates for iOS, iPadOS, macOS, and watchOS today to fix actively exploited zero-day security flaws that can be used to install malware via a &#8220;maliciously crafted image&#8221; or attachment. The iOS 16.6.1, iPadOS 16.6.1, macOS 13.5.2, and watchOS 9.6.2 updates patch the flaws across all of Apple&#8217;s platforms. As of this writing, no updates have been released for older versions like iOS 15 or macOS 12.<\/p>\n<p>The CVE-2023-41064 and CVE-2023-41061 flaws were <a href=\"https:\/\/citizenlab.ca\/2023\/09\/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild\/\">reported<\/a> by the Citizen Lab at the Munk School of Global Affairs &amp; Public Policy at the University of Toronto. Also dubbed &#8220;BLASTPASS,&#8221; Citizen Lab says that the bugs are serious because they can be exploited just by loading an image or attachment, which happens regularly in Safari, Messages, WhatsApp, and other first- and third-party apps. These bugs are also called &#8220;zero-click&#8221; or &#8220;clickless&#8221; vulnerabilities.<\/p>\n<p>Citizen Lab also said that the BLASTPASS bug was &#8220;being used to deliver NSO Group\u2019s <a href=\"https:\/\/arstechnica.com\/information-technology\/2017\/04\/found-quite-possibly-the-most-sophisticated-android-espionage-app-ever\/\">Pegasus mercenary spyware<\/a>,&#8221; the <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/07\/clickless-exploits-from-israeli-firm-hacked-activists-fully-updated-iphones\/\">latest<\/a> in a <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/10\/whatsapp-suit-says-israeli-spyware-maker-exploited-its-app-to-infect-1400-users\/\">long line<\/a> of similar exploits that have been used to infect fully patched iOS and Android devices.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1966414#p3\">Read 3 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1966414&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1966414\" target=\"_blank\" rel=\"noopener\">Apple patches \u201cclickless\u201d 0-day image processing vulnerability in iOS, macOS<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Apple) Apple has released security updates for iOS, iPadOS, macOS, and watchOS today to fix actively exploited zero-day security flaws that can be used to install malware via a &#8220;maliciously crafted image&#8221; or attachment. The iOS 16.6.1, iPadOS &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1180080\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1180081,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1180080","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1180080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1180080"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1180080\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1180081"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1180080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1180080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1180080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}