iOS 16.7 與 iPadOS 16.7 版本更新 安全性更新

iOS 16.7 與 iPadOS 16.7 版本更新 安全性更新

Apple 在2023年9月22日正式推出 iOS 16.7 與 iPadOS 16.7 版本更新,此版本更新沒有新增加功能,根據 Apple 官方的說明主要為安全性更新,主要修復了三個安全性問題,建議所有使用者進行更新。

更新版本:iOS 16.7、iPadOS 16.7

Apple 對於 iOS 16.7 與 iPadOS 16.7更新說明

此版本更新沒有新增加功能,根據 Apple 官方的說明主要為安全性更新,修正了核心(Kernel)本地攻擊者可能能夠提升其權限,安全(Security)惡意 app 可能能夠繞過簽章驗證,網頁引擎(WebKit)處理網頁內容可能導致任意代碼執行。此次更新主要修正個三個安全性問題,建議所有使用者進行更新。

以下是 Apple 對於此版本更新說明

Kernel

Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Description: The issue was addressed with improved checks.
CVE-2023-41992: Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School and Maddie Stone of Google’s Threat Analysis Group

Security

Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Description: A certificate validation issue was addressed.
CVE-2023-41991: Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School and Maddie Stone of Google’s Threat Analysis Group

WebKit

Available for: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Description: The issue was addressed with improved checks.
WebKit Bugzilla: 261544
CVE-2023-41993: Bill Marczak of The Citizen Lab at The University of Toronto’s Munk School and Maddie Stone of Google’s Threat Analysis Group

相關文章
作者簡介
個人頭像照片
努力寫文中!