Apple Releases iOS 15.0.2 Security Update to Fix IOMFB Bug 

Apple Security Update
Share It On:

16th October 2021, Kathmandu

Mac has delivered a security update iOS 15.0.2 and iPad OS 15.0.2 to fix a zero-day weakness that is effectively taken advantage of in assaults focusing on iPhones and iPads.

The weakness, followed as CVE-2021-30883, permits an application to execute orders on weak gadgets with portion advantages. This weakness is a basic, memory debasement bug in the IOMobileFrameBuffer.

As piece advantages permit the application to execute self-assertive code on the gadget, dangerous entertainers might actually utilize it to take information or introduce further malware.

IOMobileFramebuffer is a portion expansion for dealing with the screen framebuffer. It is constrained by the client land structure IOMobileFramework.

Per the delivery, the update is for the accompanying rundown of gadgets:
  • iPhone 6s and later
  • iPad Pro (all models)
  • iPad Air 2 and later
  • iPad fifth era and later
  • iPad little 4 and later
  • iPod contact (seventh era)

CVE-2021-30883 Details

The weakness influences an obscure code square of the part IOMobileFrameBuffer. Obscure information or code can be controlled, which prompts a memory defilement weakness. This will affect privacy, honesty, and accessibility. The weakness information base archiving local area VulDB has fixed the evaluation for this adventure at around USD $10k-$25k and hopes to see the endeavor costs for this item expanding soon.

As per the Apple discharge, moving up to rendition 15.0.2 disposes of this weakness.

Stream of Vulnerabilities

Mac has been routinely delivering security refreshes for assaults against iPhones, iPads, and macOS gadgets to defend its clients from additional abuse. With the steady expansion in occurrences of information breaks and zero-day takes advantage of, clients are urged to survey security delivers and apply the updates/patches at the most punctual.


Share It On:

Recent Posts

Nepal’s Cybersecurity Crisis: Are We Prepared for the Future?

Nepal’s Cybersecurity Crisis: Are We Prepared for the Future?

Share It On:8th January 2024, Kathmandu Is Nepal ready to combat cyber threats? Explore real incidents, vulnerabilities, and actionable strategies

Ngadi Group Power Limited Opens Application for 100% Rights Offering

Ngadi Group Power Limited Opens Application for 100% Rights Offering

Share It On:7th January 2024, Kathmandu Ngadi Group Power Limited has officially opened applications for its 100% rights share issuance

Skill Fest 2025 at Embark College: Workshops, Job Fair, & CEO Unplugged

Skill Fest 2025 at Embark College: Workshops, Job Fair, &

Share It On:7th January 2024, Kathmandu Glocal After School, an entity of Glocal Pvt. Ltd., is set to launch the

Kathmandu Trash Collection Race 2025: Maina Devi Foundation & Kumari Job Partner for Change

Kathmandu Trash Collection Race 2025: Maina Devi Foundation & Kumari

Share It On:7th January 2024, Kathmandu Maina Devi Foundation (MDF), a leading non-profit organization driving environmental initiatives in Nepal, has

Certified Ethical Hacking Workshop in Bharatpur, Chitwan: Advance Your Cybersecurity Career with CEH Certification

Certified Ethical Hacking Workshop in Bharatpur, Chitwan: Advance Your Cybersecurity

Share It On:7th January 2024, Kathmandu Are you looking to step into the dynamic field of cybersecurity or enhance your

Global Money Transfer Interaction Program Concludes in Nepal

Global Money Transfer Interaction Program Concludes in Nepal

Share It On:6th January 2024, Kathmandu To promote global money transfer and explore opportunities in information technology, the Nepal Deposit