Odaily Planet Daily News Apple has released a new round of security patches to address three actively exploited zero-day vulnerabilities affecting iOS, iPadOS, macOS, watchOS and Safari, bringing the number of zero-day vulnerabilities discovered in its software this year to The total number of daily vulnerabilities reached 16.
The list of security vulnerabilities is as follows:
- CVE-2023-41991, a certificate verification issue in the Security framework that could allow malicious applications to bypass signature verification.
- CVE-2023-41992, a security vulnerability in the Kernel that could allow local attackers to escalate privileges.
- CVE-2023-41993, a vulnerability in WebKit that could lead to arbitrary code execution when processing specially crafted web content.
Apple did not provide more details, only confirming that "this issue may be actively exploited in versions prior to iOS 16.7. Users are reminded to upgrade in time." (The Hacker Wews)