Apple Updates
4076Warning Date
Severity Level
Warning Number
Target Sector
15 December, 2020
● High
2020-2199
All
Description:
Apple has released security updates to address multiple vulnerabilities in their products. Apple recommends updating the products to the following versions:
- iOS 12.5
- Available for:
- iPhone 5s
- Phone 6 and 6 Plus
- iPad Air
- iPad mini 2 and 3
- iPod touch (6th generation)
- Available for:
- iOS 14.3 and iPadOS 14.3
- Available for:
- iPhone 6s and later
- iPod touch 7th generation
- iPad Air 2 and later
- iPad mini 4 and later
- Available for:
- tvOS 14.3
- Available for:
- Apple TV 4K
- Apple TV HD
- Available for:
- watchOS 6.3
- Available for:
- Apple Watch Series 1
- Apple Watch Series 2
- Available for:
- watchOS 7.2
- Available for:
- Apple Watch Series 3 and later
- Available for:
- macOS Big Sur 11.1, 2020-001 Catalina, 2020-007 Mojave
- Available for:
- macOS Big Sur 11.0.1, macOS Catalina 10.15.7, and macOS Mojave 10.14.6
- Available for:
- macOS Server 5.11
- Available for:
- macOS Big Sur
- Available for:
- Safari 14.0.2
- Available for:
- macOS Catalina and macOS Mojave
- Available for:
Threats:
Attacker could exploit these vulnerabilities by doing the following:
- Arbitrary code execution with high privilege
- Sensitive information disclosure
- Memory corruption
- Bypass privacy preferences by a malicious application
- Cause unexpected application termination
- Privilege escalation.
- Cross-site scripting (XSS)
- Denial of Service (DoS)
- Violate authentication policy
Best practice and Recommendations:
The CERT team encourages users to review Apple security advisory and apply the necessary updates:
- https://support.apple.com/en-us/HT212003
- https://support.apple.com/en-us/HT212011
- https://support.apple.com/en-us/HT211932
- https://support.apple.com/en-us/HT212005
- https://support.apple.com/en-us/HT212009
- https://support.apple.com/en-us/HT212007
- https://support.apple.com/en-us/HT212004
- https://support.apple.com/en-us/HT212006