Sunday, January 25, 2026
This Big Influence
  • Home
  • World
  • Podcast
  • Politics
  • Business
  • Health
  • Tech
  • Awards
  • Shop
No Result
View All Result
This Big Influence
No Result
View All Result
Home Tech

Apple, Google, and Microsoft Just Fixed Zero-Day Security Flaws

ohog5 by ohog5
April 30, 2023
in Tech
0
Apple, Google, and Microsoft Just Fixed Zero-Day Security Flaws
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


You might also like

OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents

2 moral actions shape first impressions more than others

DOGE May Have Misused Social Security Data, DOJ Admits

Tech giants Apple, Microsoft, and Google every fastened main safety flaws in April, a lot of which had been already being utilized in real-life assaults. Different corporations to difficulty patches embrace privacy-focused browser Firefox and enterprise software program suppliers SolarWinds and Oracle.

Right here’s all the things you must know in regards to the patches launched in April.

Apple

Sizzling on the heels of iOS 16.4, Apple has launched the iOS 16.4.1 update to repair two vulnerabilities already being utilized in assaults. CVE-2023-28206 is a matter within the IOSurfaceAccelerator that might see an app in a position to execute code with kernel privileges, Apple stated on its support page.

CVE-2023-28205 is a matter in WebKit, the engine that powers the Safari browser, that might result in arbitrary code execution. In each instances, the iPhone maker says, “Apple is conscious of a report that this difficulty might have been actively exploited.”

The bug means visiting a booby-trapped web site might give cybercriminals management over your browser—or any app that makes use of WebKit to render and show HTML content material, says Paul Ducklin, a safety researcher at cybersecurity agency Sophos.

The 2 flaws fastened in iOS 16.4.1 had been reported by Google’s Risk Evaluation Group and Amnesty Worldwide’s Safety Lab. Taking this under consideration, Ducklin thinks the safety holes might have been used for implanting spy ware.

Apple additionally launched iOS 15.7.5 for customers of older iPhones to repair the identical already exploited flaws. In the meantime, the iPhone maker issued macOS Ventura 13.3.1, Safari 16.4.1, macOS Monterey 12.6.5, and macOS Massive Sur 11.7.6.

Microsoft

Apple wasn’t the one large tech agency issuing emergency patches in April. Microsoft additionally launched an pressing repair as a part of this month’s Patch Tuesday replace. CVE-2023-28252 is an elevation-of-privilege bug within the Home windows Frequent Log File System Driver. An attacker who efficiently exploited the flaw might achieve system privileges, Microsoft stated in an advisory.

One other notable flaw, CVE-2023-21554, is a distant code execution vulnerability in Microsoft Message Queuing labeled as having a essential impression. To use the vulnerability, an attacker would wish to ship a malicious MSMQ packet to an MSMQ server, Microsoft stated, which might end in distant code execution on the server facet.

The repair was a part of a slew of patches for 98 vulnerabilities, so it’s price trying out the advisory and updating as quickly as potential.

Google Android

Google has issued a number of patches for its Android working system, fixing a number of severe holes. Essentially the most extreme bug is a essential safety vulnerability within the system element that might result in distant code execution with no further execution privileges wanted, Google stated in its Android Security Bulletin. Person interplay is just not wanted for exploitation.

The patched points embrace 10 within the framework, together with eight elevation-of-privilege flaws, and 9 others rated as having a excessive severity. Google fastened 16 bugs within the system together with two essential RCE flaws and several other points within the kernel and SoC parts.

The replace additionally contains a number of Pixel-specific patches, together with an elevation-of-privilege flaw within the kernel tracked as CVE-2023-0266. The Android April patch is accessible for Google’s units in addition to fashions including Samsung’s Galaxy S-series alongside the Fold and Flip-series.

Google Chrome

Initially of April, Google issued a patch to repair 16 points in its common Chrome browser, a few of that are severe. The patched flaws embrace CVE-2023-1810, a heap buffer overflow difficulty in Visuals rated as having a excessive impression, and CVE-2023-1811, a use-after-free vulnerability in Frames. The remaining 14 safety bugs are rated as having a medium or low impression.

Mid-month, Google was pressured to difficulty an emergency replace, this time to repair two flaws, one among which is already being utilized in real-life assaults. CVE-2023-2033 is a kind of confusion flaw within the V8 JavaScript engine. “Google is conscious that an exploit for CVE-2023-2033 exists within the wild,” the software program large stated on its blog.

Simply days later, Google released one other patch, fixing points together with one other zero-day flaw tracked as CVE-2023-2136, an integer overflow bug within the Skia graphics engine.



Source link

Tags: AppleFixedFlawsGoogleMicrosoftSecurityZeroDay
Share30Tweet19
ohog5

ohog5

Recommended For You

OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents

by ohog5
January 25, 2026
0
OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents

Illustration by Tag Hartman-Simkins / Futurism. Supply: Getty Photographs One thing unusual is occurring with ManyVids, an OnlyFans-like porn platform with tens of millions of customers. For roughly...

Read more

2 moral actions shape first impressions more than others

by ohog5
January 25, 2026
0
2 moral actions shape first impressions more than others

Share this Article You're free to share this text underneath the Attribution 4.0 Worldwide license. New analysis reveals that equity and respect for property form our first impressions—and...

Read more

DOGE May Have Misused Social Security Data, DOJ Admits

by ohog5
January 24, 2026
0
DOGE May Have Misused Social Security Data, DOJ Admits

Legislation enforcement authorities in the US have for years circumvented the US Constitution’s Fourth Amendment by purchasing data on US residents that might in any other case must...

Read more

Amazon Echo Studio deal: Save $30 with coupon code

by ohog5
January 24, 2026
0
Amazon Echo Studio deal: Save $30 with coupon code

SAVE $30: As of Jan. 23, the Amazon Echo Studio is on sale for $189.99 with the on-page coupon code ECHOSTUDIO30. That is a financial savings of about...

Read more

Twisting a Crystal at the Nanoscale Changes How Electricity Flows

by ohog5
January 23, 2026
0
Twisting a Crystal at the Nanoscale Changes How Electricity Flows

Scientists have proven that twisting a crystal on the nanoscale can flip it right into a tiny, reversible diode, hinting at a brand new period of shape-engineered electronics....

Read more
Next Post
Is MSG Bad For You? (or Not a Big Deal?)

Is MSG Bad For You? (or Not a Big Deal?)

Leave a Reply

Your email address will not be published. Required fields are marked *

Related News

Indian investors rush into highly valued defence stocks

Indian investors rush into highly valued defence stocks

January 7, 2025
Family vlogger Ruby Franke and business partner held without bail in child abuse case – NBC News

Family vlogger Ruby Franke and business partner held without bail in child abuse case – NBC News

September 9, 2023
Team links concussions to suicidal thoughts in high school athletes

Team links concussions to suicidal thoughts in high school athletes

November 17, 2023

Browse by Category

  • Business
  • Health
  • Politics
  • Tech
  • World

Recent News

OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents

OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents

January 25, 2026
Cartoon: Sanctuary Seahawks

Cartoon: Sanctuary Seahawks

January 25, 2026

CATEGORIES

  • Business
  • Health
  • Politics
  • Tech
  • World

Follow Us

Recommended

  • OnlyFans Rival Seemingly Succumbs to AI Psychosis, Which We Dare You to Try Explain to Your Parents
  • Cartoon: Sanctuary Seahawks
  • 2 moral actions shape first impressions more than others
  • Spice Bazaar celebrates its one year anniversary at store in Salisbury – delmarvanow.com
No Result
View All Result
  • Home
  • World
  • Podcast
  • Politics
  • Business
  • Health
  • Tech
  • Awards
  • Shop

© 2023 ThisBigInfluence

Cleantalk Pixel
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?