{"id":92943,"date":"2021-01-26T20:17:49","date_gmt":"2021-01-27T04:17:49","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=92943"},"modified":"2021-01-29T13:59:09","modified_gmt":"2021-01-29T21:59:09","slug":"apple-patches-actively-exploited-security-flaws-in-ios-ipados","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/","title":{"rendered":"Apple patches actively exploited security flaws in iOS, iPadOS"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-86452\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/03\/ios-software-update-available-icon-600x300-e1558142227486.png\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/03\/ios-software-update-available-icon-600x300-e1558142227486.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/03\/ios-software-update-available-icon-600x300-e1558142227486-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/03\/ios-software-update-available-icon-600x300-e1558142227486-300x150.png 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>On Tuesday, January 26, Apple released iOS and iPadOS version 14.4, which address at least <a href=\"https:\/\/support.apple.com\/en-us\/HT212146\" target=\"_blank\" rel=\"noopener\">three zero-day vulnerabilities<\/a> that have been actively exploited in the wild, as well as updates for watchOS and tvOS. Here&#8217;s a brief overview of the security flaws and what Apple has done to fix them.<\/p>\n<h3>The WebKit bugs<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-89236\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon.png\" alt=\"\" width=\"128\" height=\"128\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon.png 512w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-300x300.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-32x32.png 32w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-50x50.png 50w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-64x64.png 64w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-96x96.png 96w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/08\/Apple-Safari-browser-iOS-12-icon-128x128.png 128w\" sizes=\"auto, (max-width: 128px) 100vw, 128px\" \/>Two of the three zero-day bugs were addressed in WebKit\u2014Apple&#8217;s page rendering engine, which is used by Apple&#8217;s Safari browser and many parts of Apple operating systems.<\/p>\n<p>Apple says that because of these twin WebKit bugs, &#8220;A remote attacker may be able to cause arbitrary code execution. <strong>Apple is aware of a report that this issue may have been actively exploited.<\/strong>&#8221; The company says it fixed the issue by addressing a &#8220;logic issue [\u2026] with improved restrictions.&#8221;<\/p>\n<p>Reading between the lines, it sounds as though a victim&#8217;s iPhone or iPad could have been compromised (i.e. hacked) or exploited by an attacker, simply by the victim viewing a page or opening an e-mail created or modified by an attacker. Notably, this kind of attack may not necessarily\u00a0require the victim to click on a link within the theoretical page or e-mail.<\/p>\n<h3>The kernel bug<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-92946\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/kernel-bug-maize-weevil-usda-300x455-1.jpg\" alt=\"kernel bug (maize weevil on a corn kernel)\" width=\"128\" height=\"194\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/kernel-bug-maize-weevil-usda-300x455-1.jpg 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/kernel-bug-maize-weevil-usda-300x455-1-198x300.jpg 198w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/kernel-bug-maize-weevil-usda-300x455-1-99x150.jpg 99w\" sizes=\"auto, (max-width: 128px) 100vw, 128px\" \/>Apple has also fixed a serious flaw in the kernel, the core component of Apple&#8217;s operating systems.<\/p>\n<p>According to the company, &#8220;A malicious application may be able to elevate privileges. <strong>Apple is aware of a report that this issue may have been actively exploited.<\/strong>&#8221;<\/p>\n<p>Regarding the fix, Apple says that: &#8220;A race condition was addressed with improved locking.&#8221;<\/p>\n<p>A\u00a0<strong>race condition<\/strong> is a scenario in which a task or procedure can be done out of the proper order. Race conditions can sometimes enable an attacker to do things they shouldn&#8217;t be able to do under normal circumstances.<\/p>\n<p>A <strong>privilege elevation<\/strong> (or <strong>privilege escalation<\/strong>) vulnerability enables attacks that would normally only be possible by someone with administrator or root permissions. Such vulnerabilities can make it possible to pull off attacks that may not be possible under normal conditions, or they can enable attacks to do more damage.<\/p>\n<p>This kernel bug does not merely affect iOS and iPadOS. <strong>The same kernel bug was also patched in tvOS 14.4 and watchOS 7.3<\/strong>, both of which were released simultaneously with the iOS and iPadOS updates on Tuesday.<\/p>\n<h3>Where are the macOS updates?<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-92954\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/Finder-icon-macOS-Big-Sur-sad-face.png\" alt=\"Finder icon macOS Big Sur with sad face\" width=\"128\" height=\"128\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/Finder-icon-macOS-Big-Sur-sad-face.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/Finder-icon-macOS-Big-Sur-sad-face-300x300.png 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2021\/01\/Finder-icon-macOS-Big-Sur-sad-face-150x150.png 150w\" sizes=\"auto, (max-width: 128px) 100vw, 128px\" \/>Interestingly, Apple has yet to release corresponding macOS updates for Big Sur (macOS 11) or the two previous Mac operating systems, macOS Catalina (10.15) and macOS Mojave (10.14).<\/p>\n<p>Apple usually releases macOS updates simultaneously iOS and other operating system updates. Occasionally, however, the urgency of an in-the-wild exploit warrants releasing some patches before all of them are ready to be released.<\/p>\n<p>That seems to be the case here. On Monday, Apple released the second release candidate for macOS 11.2, so presumably the macOS updates will arrive soon.<\/p>\n<p><strong>Update:<\/strong> Apple deployed a third release candidate for macOS 11.2 on Thursday, January 28, and had not released the final version to the public by Friday. This seems to indicate that we may not see the next macOS release until around next Tuesday, February 2, or perhaps later.<\/p>\n<h3>Other bugs patched, but not yet announced<\/h3>\n<p>At the bottom of each page listing the <a href=\"https:\/\/support.apple.com\/en-us\/HT212146\" target=\"_blank\" rel=\"noopener\">iOS 14.4\/iPadOS 14.4<\/a>, <a href=\"https:\/\/support.apple.com\/en-us\/HT212149\" target=\"_blank\" rel=\"noopener\">tvOS 14.4<\/a>, and <a href=\"https:\/\/support.apple.com\/en-us\/HT212148\" target=\"_blank\" rel=\"noopener\">watchOS 7.3<\/a> security update details, Apple noted in italics, &#8220;<em><strong>Additional details available soon.<\/strong><\/em>&#8221;<\/p>\n<p>When Apple releases operating system security updates out of sync with one another, the company often holds back some details until the remaining operating systems have been patched. This may especially be true if disclosing some details could lead attackers to guess at how to exploit the OS for which patches are not yet available.<\/p>\n<p>There&#8217;s a good chance that Apple will release macOS Big Sur 11.2\u2014and presumably security-only updates for Catalina and Mojave\u2014sometime next week, so keep an eye out for those updates.<\/p>\n<p>We&#8217;ll cover any macOS-specific security bugs, as well as any of the security bugs in this week&#8217;s OS releases that Apple hasn&#8217;t yet told us about, right here on The Mac Security Blog.<\/p>\n<h3><span style=\"font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen-Sans, Ubuntu, Cantarell, 'Helvetica Neue', sans-serif;\">How can I learn more?<\/span><\/h3>\n<p><a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-71818\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png\" alt=\"\" width=\"50\" height=\"50\" data-wp-editing=\"1\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-32x32.png 32w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-50x50.png 50w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-64x64.png 64w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-96x96.png 96w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile-128x128.png 128w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/10\/ios9-podcasts-app-tile.png 300w\" sizes=\"auto, (max-width: 50px) 100vw, 50px\" \/><\/a>On this week&#8217;s episode of the <strong>Intego Mac Podcast<\/strong>, Intego&#8217;s experts discuss these new vulnerabilities and a lot more. Be sure to <a href=\"https:\/\/podcasts.apple.com\/us\/podcast\/intego-mac-podcast\/id1293834627\" target=\"_blank\" rel=\"noopener noreferrer\">subscribe<\/a> to make sure you never miss the latest episode!<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/player.fireside.fm\/v2\/GegHgcrH+oIIA2PWY?theme=dark\" width=\"740\" height=\"200\" frameborder=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Also subscribe to our <strong>e-mail newsletter<\/strong> and keep an eye here on <strong>The Mac Security Blog<\/strong> for updates.<\/p>\n<p>And make sure you&#8217;re following Intego on your favorite social and media channels: <a href=\"https:\/\/www.facebook.com\/Intego\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>, <a href=\"https:\/\/www.instagram.com\/intego_security\/\" target=\"_blank\" rel=\"noopener noreferrer\">Instagram<\/a>, <a href=\"https:\/\/twitter.com\/IntegoSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>, and <a href=\"https:\/\/www.youtube.com\/user\/IntegoVideo?sub_confirmation=1\" target=\"_blank\" rel=\"noopener noreferrer\">YouTube<\/a> (click the \ud83d\udd14 to get notified about new videos).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.<\/p>\n","protected":false},"author":14,"featured_media":85426,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,5],"tags":[201],"class_list":["post-92943","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security-privacy","category-security-news","tag-security-updates"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Joshua Long\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Apple patches actively exploited security flaws in iOS, iPadOS\" \/>\n\t\t<meta property=\"og:description\" content=\"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-01-27T04:17:49+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-01-29T21:59:09+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Apple patches actively exploited security flaws in iOS, iPadOS\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#blogposting\",\"name\":\"Apple patches actively exploited security flaws in iOS, iPadOS\",\"headline\":\"Apple patches actively exploited security flaws in iOS, iPadOS\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/ios-software-update-available-icon-400x260.png\",\"width\":400,\"height\":260,\"caption\":\"iOS software update available icon\"},\"datePublished\":\"2021-01-26T20:17:49-08:00\",\"dateModified\":\"2021-01-29T13:59:09-08:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#webpage\"},\"articleSection\":\"Security &amp; Privacy, Security News, Security Updates, joshlong\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#listItem\",\"name\":\"Apple patches actively exploited security flaws in iOS, iPadOS\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#listItem\",\"position\":3,\"name\":\"Apple patches actively exploited security flaws in iOS, iPadOS\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Joshua Long\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/\",\"name\":\"Apple patches actively exploited security flaws in iOS, iPadOS\",\"description\":\"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/joshlong\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2019\\\/01\\\/ios-software-update-available-icon-400x260.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"iOS software update available icon\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\\\/#mainImage\"},\"datePublished\":\"2021-01-26T20:17:49-08:00\",\"dateModified\":\"2021-01-29T13:59:09-08:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Apple patches actively exploited security flaws in iOS, iPadOS<\/title>\n\n","aioseo_head_json":{"title":"Apple patches actively exploited security flaws in iOS, iPadOS","description":"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#blogposting","name":"Apple patches actively exploited security flaws in iOS, iPadOS","headline":"Apple patches actively exploited security flaws in iOS, iPadOS","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/ios-software-update-available-icon-400x260.png","width":400,"height":260,"caption":"iOS software update available icon"},"datePublished":"2021-01-26T20:17:49-08:00","dateModified":"2021-01-29T13:59:09-08:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#webpage"},"articleSection":"Security &amp; Privacy, Security News, Security Updates, joshlong"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#listItem","name":"Apple patches actively exploited security flaws in iOS, iPadOS"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#listItem","position":3,"name":"Apple patches actively exploited security flaws in iOS, iPadOS","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/ed8c9b8cc8610160efb5aa95bc28a7a0d5a23ce9b8959054305b11094bf0485a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Joshua Long"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/","name":"Apple patches actively exploited security flaws in iOS, iPadOS","description":"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2019\/01\/ios-software-update-available-icon-400x260.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#mainImage","width":400,"height":260,"caption":"iOS software update available icon"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/#mainImage"},"datePublished":"2021-01-26T20:17:49-08:00","dateModified":"2021-01-29T13:59:09-08:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"Apple patches actively exploited security flaws in iOS, iPadOS","og:description":"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.","og:url":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/","article:published_time":"2021-01-27T04:17:49+00:00","article:modified_time":"2021-01-29T21:59:09+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"Apple patches actively exploited security flaws in iOS, iPadOS","twitter:description":"Apple patched three actively exploited zero-day vulnerabilities in iOS and iPadOS on Tuesday, January 26. Update now to protect your iPhone and iPad! And prepare for macOS updates that should be coming soon.","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"92943","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 21:12:32","created":"2026-09-03 21:12:32","updated":"2026-09-04 16:49:18","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tApple patches actively exploited security flaws in iOS, iPadOS\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"Apple patches actively exploited security flaws in iOS, iPadOS","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-patches-actively-exploited-security-flaws-in-ios-ipados\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=92943"}],"version-history":[{"count":14,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92943\/revisions"}],"predecessor-version":[{"id":92960,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/92943\/revisions\/92960"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/85426"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=92943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=92943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=92943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}