Security Researchers Delve Into Major Vulnerability Patched in iOS 16.3 and macOS 13.2

With almost every iOS and macOS update, Apple includes a host of security improvements to address major vulnerabilities. iOS 16.3 and macOS Ventura 13.2, released back in January, were no exception. Both updates included fixes for a long list of issues, including two that were highlighted today in a report from Trellix.

Trellix Advanced Research Center discovered a new class of privilege execution bugs within iOS and macOS, which could be exploited to delve into an iPhone or Mac user’s messages, location data, photos, call history, and more.

In a blog post highlighting how the bug was found, Trellix explains how mitigations that Apple introduced for the FORCEDENTRY zero-click exploit in September 2021 could by bypassed, allowing for a “huge range of potential vulnerabilities.”

Trellix found its first vulnerability in the coreduetd process, which could be used to give an attacker access to a person’s calendar, address book, and photos. Vulnerabilities in OSLogService and NSPredicate were able to be exploited to achieve code execution within Springboard, providing attackers access to the camera, microphone, call history, and more.

Data about these vulnerabilities was relayed to Apple, and the company fixed the exploits in iOS 16.3 and macOS 13.2 Ventura. Security support documents for both updates were refreshed yesterday to reflect the addition of the patches.

Trellix is credited with two vulnerabilities (CVE-2023-23530 and CVE-2023-23531) that Apple patched with improved memory handling. Trellix said that it thanks Apple for working quickly to fix the issues.
This article, “Security Researchers Delve Into Major Vulnerability Patched in iOS 16.3 and macOS 13.2” first appeared on MacRumors.com

Discuss this article in our forums

Related posts

Latest posts

Android 16 brings a blind fingerprint unlock perk to Pixel phones

The latest beta build of Android 16 brings a new feature to Pixel phones that lets users biometrically unlock the device without ever waking up the screen.

Vibe coding: What it is, and why you should give it a miss

Imagine building an entire app without typing a single line of code -- the vibe coding trend says it's possible, but I have big doubts.

Nvidia RTX 5070 Ti review: the right GPU at the wrong time

The RTX 5070 Ti offers great performance, only if you can find one at retail pricing.

Nvidia may finally let gamers buy some GPUs at a reasonable price

Nvidia is readying the RTX 5060 Ti and the RTX 5060, and it might have a plan to ensure people can get it at MSRP.

A helpful Galaxy phone feature is getting some much-needed attention

Samsung is working with popular app developers in South Korea to improve its helpful, but underutilized, Now Bar feature available on new Galaxy phones.

Google accidentally deleted users’ data, but there’s no apology in sight

Google has accidentally deleted Google Maps Timeline data for some users, and if you didn't have backups turned on, you can't get it back.

Driver issues with Nvidia GPUs? No, it’s not just you

If you're the owner of an Nvidia RTX 40-series GPU, you might be in for some problems if you try the latest drivers.

The best Google Pixel 9a cases

Table of Contents Table of Contents OtterBox Commuter Series Spigen Liquid Air Zagg Crystal Palace Google Pixel 9a Case Speck ImpactHero Slim Caka for Pixel 9a Natbok Magnetic Bellroy Leather Pixel 9a Case The...

AMD’s new 9070 XT beats all but one Radeon GPU

AMD’s and that goes for almost everything that came before, too. Although AMD didn’t market its new card as a high-end option, it might as well have, because it can beat almost any other AMD graphics card you pit it against. Even potentially . But that last-gen card does have more memory, compute units, and […]

Moto Razr Plus (2025) expected to launch with a big hardware upgrade

Motorola is preparing to launch its 2025 phones and the model most likely to attract your attention is the Razr Plus (2025). Moto’s flagship folding phone has previously leaked, showing us what to  – spoiler, it’s not that different to the 2024 model – but there could be some surprises inside the phone. The new […]