Beware! Government Warns iPhone, Mac, iPad Users Against Critical Vulnerabilities in Apple’s Products



The Indian Computer Emergency Response Team (CERT-In) has issued an advisory, warning users of iPhone, iPad, Mac, and other Apple devices of critical security vulnerabilities that could let hackers gain access to sensitive user information, including phone numbers, banking details, and passwords. According to the government agency, a part of the Ministry of Electronics and Information Technology, the vulnerabilities exist in old software versions of the iPhone, iPad, Mac, Apple TV, Apple Watch, and even the Vision Pro headset, which is officially unavailable in India. However, the latest updates for each device come with a fix.

CERT-In has identified one of the vulnerabilities, ‘CVE-2025-24085’, as “critical”, underscoring that it has been “actively” exploited in the wild. It is a use-after-free bug in Apple’s Core Media component, which hackers may exploit to “gain elevated privileges on the affected devices.” Other vulnerabilities have occurred due to multiple data handling errors and bugs, per the report.

Categorised as “high risk,” the security flaws target devices running macOS Sequoia versions prior to 15.3, macOS Sonoma versions before 14.7.3, macOS Ventura versions prior to 13.7.3, iPadOS versions prior to 18.3 and 17.7.4, iOS versions prior to 18.3, tvOS versions before 18.3, watchOS versions prior to 11.3, and visionOS versions before 2.3. Apple’s Safari browser versions before 18.3 are also affected by the vulnerabilities, which CERT-In said also allow malicious actors to “execute arbitrary code, bypass security restrictions, cause denial of service (DoS) conditions, bypass authentication, gain elevated privileges, data manipulation, and perform spoofing attacks on the targeted system.”

The government agency has urged users of impacted devices to update the software to the latest versions to mitigate potential hacking attempts. Apple users can go to their device’s software update settings and check for the latest versions. Before moving ahead with the installation process, it is advisable to back up the data stored on the device.



Source link

  • Related Posts

    Lupin, China’s SUP ink pact for COPD drug Tiotropium DPI

    Lupin has signed a license and supply agreement with Sino Universal Pharmaceuticals (SUP) for commercialisation of chronic obstructive pulmonary disease drug Tiotropium Dry Powder Inhaler, 18 mcg/capsule, in the Chinese…

    Continue reading
    India to export 150 locomotives to Africa worth over ₹3,000 crore

    “These locomotives are fitted with Distributed Power Wireless Control System, or DPWCS, for synchronised operations and superior freight handling,” a Railways Ministry spokesperson said. Photo: https://www.wabteccorp.com/ India will supply 150…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *