Newsletter Archives
-
Apple zero days fixed – November 30, 2023
End of the month zero days for Apple
Apple pushed updates for 2 new zero-days that may have been actively exploited.CVE-2023-42916 (WebKit),
CVE-2023-42917 (WebKit):
– iOS & iPadOS 17.1.2
– macOS Sonoma 14.1.2
– Safari 17.1.2Link at the Apple site
-
M3 powers new MacBook Pros and iMac
APPLE NEWS
By Will Fastie
Apple is infamous for making nebulous comparisons, but this time it has gone too far.
Apple’s dark (Halloween) event a week ago was mildly disappointing. The company finally got around to announcing its previously expected M3 family of silicon and refreshed the MacBook Pro series as a result.
The problem is that it wasn’t all that exciting. With a few exceptions, these were moves the company had to make, even though they will not generate the same sort of excitement as previous M1 and M2 announcements.
The centerpiece of the event was silicon, a set of chips Apple calls “the most advanced chips ever built for a personal computer.”
Read the full story in our Plus Newsletter (20.45.0, 2023-11-06).
-
Apple security updates October 25, 2023
Apple is out with some security updates today:
Like with any device – ensure you have a backup BEFORE installing updates. No actively exploited bugs are included in this batch, but there are interesting bugs that are getting squashed.
I’ll be adding this to the master list tonight and tracking any side effects.
iOS 17.1 and iPadOS 17.1 iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later iOS 16.7.2 and iPadOS 16.7.2 iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later iOS 15.8 and iPadOS 15.8 iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) macOS Sonoma 14.1 macOS Sonoma macOS Ventura 13.6.1 macOS Ventura macOS Monterey 12.7.1 macOS Monterey tvOS 17.1 Apple TV HD and Apple TV 4K (all models) watchOS 10.1 Apple Watch Series 4 and later Safari 17.1 macOS Monterey and macOS Ventura -
Apple zero days out – September 2023
Apple has fixes for zero days that have been under attack. It appears most are triggered by a specially crafted web content.
- CVE-2023-41991 – A certificate validation issue in the Security framework that could allow a malicious app to bypass signature validation.
- CVE-2023-41992 – A security flaw in Kernel that could allow a local attacker to elevate their privileges.
- CVE-2023-41993 – A WebKit flaw that could result in arbitrary code execution when processing specially crafted web content.
iOS and iPadOS 17.0.1 – 3 bugs fixed
iOS and iPadOS 16.7 – 3 bugs fixed
watchOS 9.6.3 – 2 bugs fixed
watchOS 10.0.1 – 2 bugs fixed
macOS Ventura 13.6 – 3 bugs fixed
macOS Monterey 12.7 – 1 bug fixed
Mind you iOS 17 *just* came out the other day.
These security vulnerabilities have been seen in attacks in the wild.
-
Apple 2030
ISSUE 20.38 • 2023-09-18 APPLE NEWS
By Will Fastie
Mother Nature deems Apple’s ambitious clean-energy goals worthy, albeit surprising.
Oscar winner Octavia Spencer, in her starring role as Mother Nature in Apple’s fall event, stole the show. Apple goes Hollywood all the time in these events, but this was different.
In a nicely done surprise skit, Mother Nature has come to Apple to audit its progress on meeting its green goals, specifically carbon neutrality. This alone was funny because all companies seem to have stated goals, but it’s hard to know whether any are being achieved. Mother Nature was skeptical to the point of assuming Apple was just blowing smoke, so to speak.
Read the full story in our Plus Newsletter (20.38.0, 2023-09-18).
This story also appears in our public Newsletter. -
Apple releases new security updates – June 21
iOS and iPadOS 15.7.7 – 3 bugs fixed
macOS Ventura 13.4.1 – 2 bugs fixed
iOS and iPadOS 16.5.1 – 2 bugs fixed
watchOS 9.5.2 – 1 bug fixed
watchOS 8.8.1 – 1 bug fixed
macOS Monterey 12.6.7 – 1 bug fixed
Apple pushed updates for 3 new zero-days that may have been actively exploited.
As we move to more and more of us using phones as our daily tool, so too are the attackers going after the phones with zero days
-
The last shoe drops
APPLE NEWS
By Will Fastie
Three major announcements from Apple during WWDC 2023 close the loop for Apple silicon.
No, I’m not talking about Apple Vision Pro, Apple’s new “spatial” computer.
The big news is that Apple’s product lineup no longer includes Macs with Intel silicon.
Read the full story in our Plus Newsletter (20.24.0, 2023-06-12).
-
Apple security updates for May
Apple security updates out…
macOS Ventura 13.4 – 51 bugs fixed
iOS and iPadOS 16.5 – 39 bugs fixed
watchOS 9.5 – 32 bugs fixed
macOS Monterey 12.6.6 – 29 bugs fixed
tvOS 16.5 – 28 bugs fixed
macOS Big Sur 11.7.7 – 25 bugs fixed
iOS and iPadOS 15.7.6 – 17 bugs fixed
Safari 16.5 – 5 bugs fixed
Three zero days fixed in this batch