Cybersecurity Advisory – Urgent iOS Update

14th October 2021 | Advisory, Blog Cybersecurity Advisory – Urgent iOS Update


apple ios update

October 13th, 2021:  CyberHoot received notification of a Zero-Day Vulnerability on Apple’s iPhone and iPad very latest iOS version 15 which shipped pre-installed on the latest iPhones released in Oct. Many people won’t have upgraded to this version of iOS yet, however, if you have, you need to apply this patch immediately.  Apple’s security update for iOS 15.0.2 and iPadOS 15.0.2 fixes a remote code execution (RCE) zero-day vulnerability that’s being actively exploited by hackers.

Apple iOS Critical Risk

On October 11th Apple released a critical update to its iOS and iPadOS devices, version 15.0.2. This update is critical, as it includes a patch that covers vulnerability CVE-2021-30883

Here is the notice from Apple:
IOMobileFrameBuffer
Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

Impact: An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

Description: A memory corruption issue was addressed with improved memory handling.

CVE-2021-30883: an anonymous researcher

What Does Apple Vulnerability Mean for SMBs and MSPs?

If you’ve upgraded to the latest iOS version 15 on your devices, you should update your Apple devices as soon as possible to avoid the risk of “Remote Code Execution” which translates to hackers can easily break into your device and steal your data.

In the advisory sent out by Apple, they said, “this issue may have been actively exploited“, which you can translate as “this is a zero-day bug that hackers already know how to exploit“.

Zero-days, are working attacks that the hackers have found first, so even the best-informed IT professionals in the world have had zero days during which they could have patched ahead of the crooks attacking. In other words, patch right now. 

What Should I Do?

Even if you’ve enabled automatic updates, check whether you have received the update yet. If you check and you already have 15.0.2, you are safe for now; if you don’t have 15.0.2 then your phone will offer to get it for you right away – do it! 

The area to go to is Settings > General > Software Update.

Sources
Apple Releases Urgent iOS Updates to Patch New Zero-Day Bug

Apple Security Update

Zero Day – Cybrary Term

Find out how CyberHoot can secure your business.


Schedule a demo

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

CyberHoot Newsletter – June 2025

CyberHoot Newsletter – June 2025

CyberHoot June Newsletter: Stay Informed, Stay Secure Welcome to the June edition of CyberHoot’s newsletter,...

Read more
Make Phishing Training Count with HootPhish

Make Phishing Training Count with HootPhish

Stop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...

Read more
Apple Alert: Critical AirPlay Vulnerabilities Expose Millions to Cyber Threats

Apple Alert: Critical AirPlay Vulnerabilities Expose Millions to Cyber Threats

A recent discovery by cybersecurity firm Oligo Security has unveiled a series of critical vulnerabilities in...

Read more