Apple fixes this year’s first actively exploited zero-day bug – BleepingComputer
UnitedHealth now says 190 million impacted by 2024 data breachClone2Leak attacks exploit Git flaws to steal credentialsMicrosoft Teams phishing attack alerts coming to everyone next monthMicrosoft to deprecate WSUS driver synchronization in 90 daysHackers exploiting flaws in SimpleHelp RMM to breach networksGoogle to kill Chrome Sync on older Chrome browser versionsExplore 17 different career paths with this CompTIA course bundle dealGarmin GPS watches crashing, stuck in triangle ‘reboot loop’How to access the Dark Web using the Tor BrowserHow to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11How to use the Windows Registry EditorHow to backup and restore the Windows RegistryHow to start Windows in Safe ModeHow to remove a Trojan, Virus, Worm, or other MalwareHow to show hidden files in Windows 7How to see hidden files in WindowsRemove the Theonlinesearch.com Search RedirectRemove the Smartwebfinder.com Search RedirectHow to remove the PBlock+ adware browser extensionRemove the Toksearches.xyz Search RedirectRemove Security Tool and SecurityTool (Uninstall Guide)How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundoHow to remove Antivirus 2009 (Uninstall Instructions)How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKillerLocky Ransomware Information, Help Guide, and FAQCryptoLocker Ransomware Information Guide and FAQCryptorBit and HowDecrypt Information Guide and FAQCryptoDefense and How_Decrypt Ransomware Information Guide and FAQQualys BrowserCheckSTOPDecrypterAuroraDecrypterFilesLockerDecrypterAdwCleanerComboFixRKillJunkware Removal TooleLearningIT Certification CoursesGear + GadgetsSecurityBest VPNsHow to change IP addressAccess the dark web safelyBest VPN for YouTubeApple has released security updates to fix this year’s first zero-day vulnerability, tagged as actively exploited in attacks targeting iPhone users.The zero-day fixed today is tracked as CVE-2025-24085 [iOS/iPadOS, macOS, tvOS, watchOS, visionOS] and is a privilege escalation security flaw in Apple’s Core Media framework.”A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2,” Apple said today.According to the company’s official documentation, Core Media “defines the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms.”Apple has fixed CVE-2024-23222 with improved memory management in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3.The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:Apple has yet to attribute the discovery of this security vulnerability to a security researcher and has not published details regarding attacks, even though it disclosed that it is exploited in the wild.While this zero-day bug was likely only exploited in targeted attacks, it is highly advised to install today’s security updates as soon as possible to block potentially ongoing attack attempts.Last year, the company fixed a total of six zero-days, the first in January, two in March, a fourth in May, and two more in November,One year before, in 2023, Apple patched 20 zero-day flaws exploited in the wild, including:Fortinet warns of auth bypass zero-day exploited to hijack firewallsPhishing texts trick Apple iMessage users into disabling protectionIvanti zero-day attacks infected devices with custom malwareNew Android NoviSpy spyware linked to Qualcomm zero-day bugsJapan warns of IO-Data zero-day router flaws exploited in attacksNot a member yet? Register NowPayPal to pay $2 million settlement over 2022 data breachRansomware gang uses SSH tunnels for stealthy VMware ESXi accessUnitedHealth now says 190 million impacted by 2024 data breachGet the GOAT Guide to learn how to start validating, start defending, and start winning.Generative AI: An MFA Game Changer for Security and Hacker StrategyCriminal IP Teams Up with OnTheHub for Digital Education CybersecurityPassword health-check overdue? Audit your Active Directory for freeStruggling with Security? Learn how VisionX + Splunk has you coveredTerms of Use – Privacy Policy – Ethics Statement – Affiliate DisclosureCopyright @ 2003 – 2025 Bleeping Computer® LLC – All Rights ReservedNot a member yet? Register NowRead our posting guidelinese to learn what content is prohibited.