{"id":99941,"date":"2024-03-07T02:15:19","date_gmt":"2024-03-07T10:15:19","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=99941"},"modified":"2024-04-09T19:57:12","modified_gmt":"2024-04-10T02:57:12","slug":"update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/","title":{"rendered":"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-97208\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-600x300-1.png\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-600x300-1.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-600x300-1-300x150.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-600x300-1-150x75.png 150w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>On Tuesday, March 5, Apple released significant operating system updates for iPhone and iPad. The iOS 17.4 and iPadOS 17.4 updates include new features as well as critical security updates. Let&#8217;s explore everything you should know about what Apple changed.<\/p>\n<p><strong>Update: <a href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sonoma-14-4-introduces-68-security-fixes-but-also-some-new-bugs\/\">Apple released updates for macOS, etc. on Thursday, March 7.<\/a> <\/strong>Now that Apple has released more details about the iOS security updates, we&#8217;ve noted this below.<\/p>\n<p><em>In this article:<\/em><\/p>\n<ul>\n<li><a href=\"#17\">iOS 17.4 and iPadOS 17.4<\/a><\/li>\n<li><a href=\"#16\">iOS 16.7.6 and iPadOS 16.7.6<\/a><\/li>\n<li><a href=\"#howinstall\">How to install Apple security updates<\/a><\/li>\n<li><a href=\"#learnmore\">How can I learn more?<\/a><a name=\"17\"><\/a><\/li>\n<\/ul>\n<h3>iOS 17.4 and iPadOS 17.4<\/h3>\n<p><strong>Available for:<\/strong><br \/>\niPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later<\/p>\n<h4><strong>Non-security changes in iOS 17.4 and iPadOS 17.4<\/strong><\/h4>\n<p>Apple&#8217;s <a href=\"https:\/\/support.apple.com\/en-us\/109043\" target=\"_blank\" rel=\"noopener\">iOS 17 release notes<\/a> detail a number of significant changes, including the following.<\/p>\n<ul>\n<li>There are <a href=\"https:\/\/blog.emojipedia.org\/ios-17-4-emoji-changelog\/\" target=\"_blank\" rel=\"noopener\">new emoji<\/a>; these include a broken chain, a lime, an edible mushroom, a phoenix, and nodding and shaking heads. Apple also introduced variations of 18 existing people emoji; they can now face either direction.<\/li>\n<li>Apple Podcasts now includes transcripts, with text that highlights in sync with the audio in English, French, German, and Spanish.<\/li>\n<\/ul>\n<p>There are other significant changes in iOS 17.4 that Apple did not mention in its release notes. Exclusively in EU countries (due to the new Digital Markets Act), <a href=\"https:\/\/www.intego.com\/mac-security-blog\/changes-coming-to-apple-app-stores-browsers-and-contactless-payments-in-the-eu\/\">iOS 17 now supports third-party app stores<\/a>. Additionally, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/changes-coming-to-apple-app-stores-browsers-and-contactless-payments-in-the-eu\/\">browsers can use their own rendering engines<\/a>, just like on desktop computers and Android phones; Apple no longer forces developers to use its WebKit engine on iOS. These changes are notably absent from iPadOS 17.4 because the European Commission has not declared iPads to be subject to the DMA. And, of course, non-EU countries do not get these changes, either.<\/p>\n<h4><strong>Security fixes and improvements in iOS 17.4 and iPadOS 17.4<\/strong><\/h4>\n<p>On the company&#8217;s <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" target=\"_blank\" rel=\"noopener\">security release notes page<\/a>, Apple links to <a href=\"https:\/\/support.apple.com\/en-us\/HT214081\" target=\"_blank\" rel=\"noopener\">details<\/a> about some of the security issues patched in iOS and iPadOS 17.4:<\/p>\n<blockquote><p><strong>Accessibility<\/strong><\/p>\n<p>Impact: An app may be able to read sensitive location information<\/p>\n<p>Description: A privacy issue was addressed with improved private data redaction for log entries.<\/p>\n<p>CVE-2024-23243: Cristian Dinca of &#8220;Tudor Vianu&#8221; National High School of Computer Science, Romania<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Kernel<\/strong><\/p>\n<p>Impact: An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. <strong><span style=\"color: #ff0000;\">Apple is aware of a report that this issue may have been exploited<\/span><\/strong>.<\/p>\n<p>Description: A memory corruption issue was addressed with improved validation.<\/p>\n<p>CVE-2024-23225<\/p>\n<p>&nbsp;<\/p>\n<p><strong>RTKit<\/strong><\/p>\n<p>Impact: An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. <strong><span style=\"color: #ff0000;\">Apple is aware of a report that this issue may have been exploited<\/span><\/strong>.<\/p>\n<p>Description: A memory corruption issue was addressed with improved validation.<\/p>\n<p>CVE-2024-23296<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Safari Private Browsing<\/strong><\/p>\n<p>Impact: A user&#8217;s locked tabs may be briefly visible while switching tab groups when Locked Private Browsing is enabled<\/p>\n<p>Description: A logic issue was addressed with improved state management.<\/p>\n<p>CVE-2024-23256: Om Kothawade<\/p><\/blockquote>\n<p>Notably, Apple states that &#8220;Additional CVE entries [are] coming soon.&#8221; Apple will probably release this additional information alongside the forthcoming releases of macOS Sonoma 14.4, tvOS 14.4, and watchOS 10.4.\u00a0<strong>Update:\u00a0<\/strong><a href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sonoma-14-4-introduces-68-security-fixes-but-also-some-new-bugs\/\">Apple updated its other operating systems<\/a>, and the total number of CVEs addressed in iOS 17.4 now appears to be 39.<\/p>\n<p>Apple also acknowledged that iOS and iPadOS 17.4 include security or privacy improvements related to AirDrop, Mail Conversation View, NetworkExtension, and Settings. The company did not specify CVE numbers or additional details, other than the names of contributors who offered Apple assistance. <strong>Update:<\/strong> Apple added several more &#8220;Additional recognitions&#8221; for iOS 17.4 upon the release of <a href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sonoma-14-4-introduces-68-security-fixes-but-also-some-new-bugs\/\">macOS Sonoma 14.4<\/a>.<a name=\"16\"><\/a><\/p>\n<h3>iOS 16.7.6 and iPadOS 16.7.6<\/h3>\n<p><strong>Available for:<\/strong><br \/>\niPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation<\/p>\n<p>Apple released a security-only update for iOS and iPadOS 16 for older devices that the 17 versions do not support. However, as is typical, Apple did not patch all security flaws for the older operating systems. While the 17 versions address at least four vulnerabilities with CVE numbers, and at least four other security issues for which Apple didn&#8217;t assign CVEs, <strong>iOS and iPadOS 16.7.6 only address the &#8220;exploited&#8221; kernel vulnerability, CVE-2024-23225<\/strong>.<\/p>\n<p>Intego has reached out to Apple seeking clarification whether CVE-2024-23296 (the &#8220;exploited&#8221; RTKit issue) or CVE-2024-23243 (the Accessibility privacy issue) impact iOS or iPadOS 16. If Apple responds (which is unlikely, based on Apple&#8217;s track record), we will update this article.<\/p>\n<p>CVE-2024-23256 (the Safari Private Browsing issue) does not apply to iOS or iPadOS 16; Apple introduced Locked Private Browsing in iOS and iPadOS 17.<\/p>\n<p><strong>Update:<\/strong> After releasing a related round of <a href=\"https:\/\/www.intego.com\/mac-security-blog\/macos-sonoma-14-4-introduces-68-security-fixes-but-also-some-new-bugs\/\">updates for its other operating systems<\/a>, the total number of <a href=\"https:\/\/support.apple.com\/en-us\/HT214082\">patches for iOS 16.7.6<\/a> now appears to be 19. Note that this is significantly fewer than the 39 vulnerabilities that Apple addressed in iOS 17.4.<a name=\"howinstall\"><\/a><\/p>\n<h3>How to install Apple security updates<\/h3>\n<p>Due to the severity and in-the-wild exploitation of two of the vulnerabilities, it is ideal to update as soon as you can.<\/p>\n<p>On your <strong>iPhone or iPad<\/strong>, you can go to <strong>Settings<\/strong> &gt; <strong>General<\/strong> &gt; <strong>Software Update<\/strong> to update iOS or iPadOS. (Apple calls this an &#8220;over the air&#8221; or OTA update.) Alternatively, you can connect your device to your Mac, click on the device name in a Finder window sidebar, and check for updates there. You can also back up and update your device by connecting it to a Windows PC and using the <a href=\"https:\/\/apps.microsoft.com\/detail\/9np83lwlpz9k?hl=en-us&amp;gl=US\">Apple Devices app<\/a> from the Microsoft Store.<\/p>\n<p>Whenever you&#8217;re preparing to update macOS, iOS, or iPadOS, it&#8217;s a good idea to always <strong>back up your data<\/strong> before installing any updates. This gives you a restore point if something does not go as planned. See our article on <a href=\"https:\/\/www.intego.com\/mac-security-blog\/should-you-back-up-your-ios-device-to-icloud-or-itunes\/\">how to back up your iPhone or iPad to iCloud and to your Mac<\/a>.<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"nk4R265lP5\"><p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/should-you-back-up-your-ios-device-to-icloud-or-itunes\/\">Should you back up your iPhone to iCloud or your Mac? Here&#8217;s how to do both<\/a><\/p><\/blockquote>\n<p><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;Should you back up your iPhone to iCloud or your Mac? Here&#8217;s how to do both&#8221; &#8212; The Mac Security Blog\" src=\"https:\/\/www.intego.com\/mac-security-blog\/should-you-back-up-your-ios-device-to-icloud-or-itunes\/embed\/#?secret=nk4R265lP5\" data-secret=\"nk4R265lP5\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><a name=\"learnmore\"><\/a><\/p>\n<h3 id=\"exploremore\">How can I learn more?<\/h3>\n<p>We discussed the March 5 security updates on <a href=\"https:\/\/www.intego.com\/mac-security-blog\/unintended-consequences-of-third-party-ios-app-stores-intego-mac-podcast-episode-334\/\">episode 334<\/a> of the Intego Mac Podcast.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/player.fireside.fm\/v2\/GegHgcrH+c3av9UQW?theme=dark\" width=\"740\" height=\"200\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"><img class=\"alignleft\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/04\/intego-podcast-artwork-400.jpg\" alt=\"\" width=\"80\" \/><\/a>Each week on the <a href=\"https:\/\/podcast.intego.com\/\" target=\"_blank\" rel=\"noopener\"><strong>Intego Mac Podcast<\/strong><\/a>, Intego&#8217;s Mac security experts discuss the latest Apple news, security and privacy stories, and offer practical advice on getting the most out of your Apple devices. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" rel=\"noopener\"><strong>follow the podcast<\/strong><\/a> to make sure you don\u2019t miss any episodes.<\/p>\n<p>You can also subscribe to our <a href=\"https:\/\/www.intego.com\/mac-security-blog\/mac-security-newsletter\/\"><strong>e-mail newsletter<\/strong><\/a> and keep an eye here on <a href=\"https:\/\/www.intego.com\/mac-security-blog\"><strong>The Mac Security Blog<\/strong><\/a> for the latest Apple security and privacy news. And don&#8217;t forget to follow Intego on your favorite social media channels: <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on \ud835\udd4f\/Twitter\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/X-Twitter-logo-icon-225.gif\" alt=\"Follow Intego on X\/Twitter\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Facebook\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Facebook-logo-icon-225.gif\" alt=\"Follow Intego on Facebook\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on YouTube\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/YouTube-logo-icon-225.png\" alt=\"Follow Intego on YouTube\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.pinterest.com\/intego\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(0, 0, 0, 0.2); border-radius: 8px;\" title=\"Follow Intego on Pinterest\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Pinterest-logo-icon-225.png\" alt=\"Follow Intego on Pinterest\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/intego\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on LinkedIn\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/LinkedIn-logo-icon-225.gif\" alt=\"Follow Intego on LinkedIn\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow Intego on Instagram\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2024\/03\/Instagram-logo-icon-225.gif\" alt=\"Follow Intego on Instagram\" width=\"16\" \/><\/a>\u00a0<a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener\"><img style=\"border-width: 1px; border-style: solid; border-color: rgba(255, 255, 255, 0.2); border-radius: 8px;\" title=\"Follow the Intego Mac Podcast on Apple Podcasts\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png\" alt=\"Follow the Intego Mac Podcast on Apple Podcasts\" width=\"16\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.<\/p>\n","protected":false},"author":14,"featured_media":97207,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[69,4645,4684,201],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-07T10:15:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-10T02:57:12+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png\",\"width\":400,\"height\":260,\"caption\":\"Apple software update red critical urgent actively exploited zero-day vulnerability\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/\",\"name\":\"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage\"},\"datePublished\":\"2024-03-07T10:15:19+00:00\",\"dateModified\":\"2024-04-10T02:57:12+00:00\",\"description\":\"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities\",\"datePublished\":\"2024-03-07T10:15:19+00:00\",\"dateModified\":\"2024-04-10T02:57:12+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage\"},\"wordCount\":1068,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png\",\"keywords\":[\"iOS\",\"iOS 16\",\"iOS 17\",\"Security Updates\"],\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities - The Mac Security Blog","og_description":"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.","og_url":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2024-03-07T10:15:19+00:00","article_modified_time":"2024-04-10T02:57:12+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png","width":400,"height":260,"caption":"Apple software update red critical urgent actively exploited zero-day vulnerability"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/","name":"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage"},"datePublished":"2024-03-07T10:15:19+00:00","dateModified":"2024-04-10T02:57:12+00:00","description":"This week, Apple released iOS 17.4 and iPadOS 17.4, patching at least two in-the-wild exploited security vulnerabilities. The iOS update also supports third-party app marketplaces and non-WebKit browser engines, but only in EU countries.","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"Update now: iOS 17.4 and iPadOS 17.4 fix 2 zero-day vulnerabilities","datePublished":"2024-03-07T10:15:19+00:00","dateModified":"2024-04-10T02:57:12+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#webpage"},"wordCount":1068,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png","keywords":["iOS","iOS 16","iOS 17","Security Updates"],"articleSection":["Security &amp; Privacy"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/update-now-ios-17-4-and-ipados-17-4-fix-at-least-2-zero-day-vulnerabilities\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2023\/02\/Apple-software-update-red-critical-urgent-400x260-1.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-pZX","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/99941"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=99941"}],"version-history":[{"count":17,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/99941\/revisions"}],"predecessor-version":[{"id":100202,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/99941\/revisions\/100202"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/97207"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=99941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=99941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=99941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}