Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,558
30,889


Apple today provided details about the security fixes included in last week's iOS 17.4.1 and iPadOS 17.4.1 software updates for the iPhone and iPad.

iOS-17.4.1-Includes-These-Security-Fixes-Feature.jpg

In a support document, Apple said the updates patch an image-related security vulnerability that "may lead to arbitrary code execution."

The full details:
CoreMedia

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: Processing an image may lead to arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved input validation.

CVE-2024-1580: Nick Galloway of Google Project Zero

WebRTC

Available for: iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

Impact: Processing an image may lead to arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved input validation.

CVE-2024-1580: Nick Galloway of Google Project Zero
To update your iPhone or iPad, open the Settings app and tap General → Software Update.

Apple said it has patched the same vulnerability in macOS 14.4.1 and visionOS 1.1.1 as well.

Article Link: Update Your iPhone Now: iOS 17.4.1 Includes These Security Fixes
 

twolf2919

macrumors 6502
Aug 26, 2014
451
759
Well, I don't know about you guys, but for me, the update caused FaceID to no longer work. Had to reset FaceID in Settings to make it work again :-(

I think the culprit was the new "Enhance Theft Protection" feature Apple asks you to enable when the phone starts after the update. I was dumb enough to say 'yes' :-(
 

Lounge vibes 05

macrumors 68040
May 30, 2016
3,582
10,521
always good to know, now, why not publish this kind of info together with the actual release?
There was a lot of reasons that they might not have wanted to do that.
macOS coming four days after iOS being the biggest, if they’re going to patch the same security flaw best to keep it close to the vest until it’s patched on everything.
They really should be required to list all of the affected versions. iOS16 OK? iOS15 not?
16.7.6 was released at the same time.
 

jz0309

Contributor
Sep 25, 2018
10,122
26,460
SoCal
There was a lot of reasons that they might not have wanted to do that.
macOS coming four days after iOS being the biggest, if they’re going to patch the same security flaw best to keep it close to the vest until it’s patched on everything.
Even on days where all OSs are updated together, they typically do not list details, whether it is bug fixes or security updates.
 

nightfox818

macrumors newbie
Oct 10, 2018
29
34
always good to know, now, why not publish this kind of info together with the actual release?
It’s part of responsible disclosure. You delay the technical details to give as many users as possible a chance to get updated and patched before releasing the technical details. If they didn’t, they could give bad actors a chance to use the exploit.
 

jz0309

Contributor
Sep 25, 2018
10,122
26,460
SoCal
It’s part of responsible disclosure. You delay the technical details to give as many users as possible a chance to get updated and patched before releasing the technical details. If they didn’t, they could give bad actors a chance to use the exploit.
the bad actors will try anyway as they know not everyone upgrades anyways ... 2 responses in this thread alone indicating that they are not upgrading ...
 

ifxf

macrumors 6502
Jun 7, 2011
381
634
Don‘t know why they now continuously bother you to update using banners. Apparently the notification controls only apply to apps and not the OS.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.