Particle.news

Download on the App Store

India’s CERT-In Issues Urgent Alert on Critical Apple OS Vulnerabilities

Issued after Apple released iOS 18.6 plus platform updates, the advisory highlights risks of data theft, unauthorized code execution or denial-of-service for unpatched devices.

iPhone users must update their devices as soon as possible.
Millions of Apple devices at risk: CERT-In issues warning for critical security flaw

Overview

  • The Indian Computer Emergency Response Team published a high-severity bulletin on August 4 urging immediate installation of Apple security updates.
  • CERT-In’s warning details a spectrum of flaws including type confusion, use-after-free errors, out-of-bounds memory access, integer and buffer overflows, race conditions, logic mistakes, improper file parsing, insufficient input validation and flawed privilege management.
  • Devices running iOS versions before 18.6, iPadOS before 17.7.9 or 18.6, macOS Sequoia before 15.6, Sonoma before 14.7.7 or Ventura before 13.7.7, watchOS before 11.6, tvOS before 18.6 and visionOS before 2.6 are vulnerable.
  • Exploitation could enable attackers to steal sensitive data, execute arbitrary code, bypass security restrictions or trigger denial-of-service conditions on affected devices.
  • Apple has rolled out iOS 18.6 alongside updates for iPadOS, macOS, watchOS, tvOS and visionOS, and users are urged to apply the patches immediately through their device settings.