Newsletter Archives

  • Apple zero days fixed – November 30, 2023

    End of the month zero days for Apple
    Apple pushed updates for 2 new zero-days that may have been actively exploited.

    🐛 CVE-2023-42916 (WebKit),
    CVE-2023-42917 (WebKit):
    – iOS & iPadOS 17.1.2
    – macOS Sonoma 14.1.2
    – Safari 17.1.2

    Link at the Apple site

  • M3 powers new MacBook Pros and iMac

    APPLE NEWS

    Will Fastie

    By Will Fastie

    Apple is infamous for making nebulous comparisons, but this time it has gone too far.

    Apple’s dark (Halloween) event a week ago was mildly disappointing. The company finally got around to announcing its previously expected M3 family of silicon and refreshed the MacBook Pro series as a result.

    The problem is that it wasn’t all that exciting. With a few exceptions, these were moves the company had to make, even though they will not generate the same sort of excitement as previous M1 and M2 announcements.

    The centerpiece of the event was silicon, a set of chips Apple calls “the most advanced chips ever built for a personal computer.”

    Read the full story in our Plus Newsletter (20.45.0, 2023-11-06).

  • Apple security updates October 25, 2023

    Apple is out with some security updates today:

    Like with any device – ensure you have a backup BEFORE installing updates.  No actively exploited bugs are included in this batch, but there are interesting bugs that are getting squashed.

    I’ll be adding this to the master list tonight and tracking any side effects.

    iOS 17.1 and iPadOS 17.1 iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
    iOS 16.7.2 and iPadOS 16.7.2 iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
    iOS 15.8 and iPadOS 15.8 iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
    macOS Sonoma 14.1 macOS Sonoma
    macOS Ventura 13.6.1 macOS Ventura
    macOS Monterey 12.7.1 macOS Monterey
    tvOS 17.1 Apple TV HD and Apple TV 4K (all models)
    watchOS 10.1 Apple Watch Series 4 and later
    Safari 17.1 macOS Monterey and macOS Ventura
  • Apple zero days out – September 2023

    Apple has fixes for zero days that have been under attack. It appears most are triggered by a specially crafted web content.

    • CVE-2023-41991 – A certificate validation issue in the Security framework that could allow a malicious app to bypass signature validation.
    • CVE-2023-41992 – A security flaw in Kernel that could allow a local attacker to elevate their privileges.
    • CVE-2023-41993 – A WebKit flaw that could result in arbitrary code execution when processing specially crafted web content.

     

    📱 iOS and iPadOS 17.0.1 – 3 bugs fixed
    📱 iOS and iPadOS 16.7 – 3 bugs fixed
    ⌚ watchOS 9.6.3 – 2 bugs fixed
    ⌚ watchOS 10.0.1 – 2 bugs fixed
    💻 macOS Ventura 13.6 – 3 bugs fixed
    💻 macOS Monterey 12.7 – 1 bug fixed

    Mind you iOS 17 *just* came out the other day.

    These security vulnerabilities have been seen in attacks in the wild.

  • Apple 2030

    newsletter banner

    ISSUE 20.38 • 2023-09-18

    APPLE NEWS

    Will Fastie

    By Will Fastie

    Mother Nature deems Apple’s ambitious clean-energy goals worthy, albeit surprising.

    Oscar winner Octavia Spencer, in her starring role as Mother Nature in Apple’s fall event, stole the show. Apple goes Hollywood all the time in these events, but this was different.

    In a nicely done surprise skit, Mother Nature has come to Apple to audit its progress on meeting its green goals, specifically carbon neutrality. This alone was funny because all companies seem to have stated goals, but it’s hard to know whether any are being achieved. Mother Nature was skeptical to the point of assuming Apple was just blowing smoke, so to speak.

    Read the full story in our Plus Newsletter (20.38.0, 2023-09-18).
    This story also appears in our public Newsletter.

  • Apple releases new security updates – June 21

    📱 iOS and iPadOS 15.7.7 – 3 bugs fixed
    💻 macOS Ventura 13.4.1 – 2 bugs fixed
    📱 iOS and iPadOS 16.5.1 – 2 bugs fixed
    ⌚ watchOS 9.5.2 – 1 bug fixed
    ⌚ watchOS 8.8.1 – 1 bug fixed
    💻 macOS Monterey 12.6.7 – 1 bug fixed

    Apple pushed updates for 3 new zero-days that may have been actively exploited.

    As we move to more and more of us using phones as our daily tool, so too are the attackers going after the phones with zero days

  • The last shoe drops

    APPLE NEWS

    Will Fastie

    By Will Fastie

    Three major announcements from Apple during WWDC 2023 close the loop for Apple silicon.

    No, I’m not talking about Apple Vision Pro, Apple’s new “spatial” computer.

    The big news is that Apple’s product lineup no longer includes Macs with Intel silicon.

    Read the full story in our Plus Newsletter (20.24.0, 2023-06-12).

  • Apple security updates for May

    Apple security updates out…

    💻 macOS Ventura 13.4 – 51 bugs fixed
    📱 iOS and iPadOS 16.5 – 39 bugs fixed
    ⌚ watchOS 9.5 – 32 bugs fixed
    💻 macOS Monterey 12.6.6 – 29 bugs fixed
    📺 tvOS 16.5 – 28 bugs fixed
    💻 macOS Big Sur 11.7.7 – 25 bugs fixed
    📱 iOS and iPadOS 15.7.6 – 17 bugs fixed
    🌐 Safari 16.5 – 5 bugs fixed

    Three zero days fixed in this batch