{"id":169381,"date":"2024-10-05T05:59:07","date_gmt":"2024-10-05T05:59:07","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=169381"},"modified":"2024-10-06T08:50:09","modified_gmt":"2024-10-06T08:50:09","slug":"apple-ios-18-0-1","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/169381\/mobile-2\/apple-ios-18-0-1.html","title":{"rendered":"Apple iOS 18.0.1 and iPadOS 18.0.1 fix media session and passwords bugs"},"content":{"rendered":"
<\/div>\n

Apple released iOS 18.0.1 update that addressed two vulnerabilities that exposed passwords and audio snippets to attackers.<\/h2>\n\n\n\n

Apple released iOS 18.0.1 and iPadOS 18.0.1<\/strong><\/a> updates to fix two vulnerabilities, respectively tracked as CVE-2024-44207 and CVE-2024-44204.<\/p>\n\n\n\n

The company addressed the vulnerability by improving checks. The flaw was reported by Michael Jimenez and an anonymous researcher.<\/gwmw><\/gwmw><\/p>\n\n\n\n

The vulnerability CVE-2024-44207 may allow threat actors to capture short snippets of audio messages in Messages before the microphone indicator is activated.\u00a0<\/p>\n\n\n\n

The vulnerability CVE-2024-44204 is a logic issue that could potentially enable VoiceOver to read aloud users’ saved passwords. The issue was addressed with improved validation, it was reported by the researcher Bistrit Dahal.<\/gwmw><\/p>\n\n\n\n

Apple is not aware of attack in the wild exploiting the above vulnerabilities.<\/p>\n\n\n\n

Pierluigi Paganini<\/strong><\/a><\/p>\n\n\n\n

Follow me on Twitter: @securityaffairs<\/strong><\/a> and Facebook<\/strong><\/a> and Mastodon<\/a><\/p>\n\n\n\n

(<\/strong>SecurityAffairs<\/strong><\/a>\u00a0\u2013<\/strong>\u00a0hacking, iOS<\/a>)<\/strong><\/gwmw><\/gwmw><\/p>\n","protected":false},"excerpt":{"rendered":"

Apple released iOS 18.0.1 update that addressed two vulnerabilities that exposed passwords and audio snippets to attackers. Apple released iOS 18.0.1 and iPadOS 18.0.1 updates to fix two vulnerabilities, respectively tracked as CVE-2024-44207 and CVE-2024-44204. The company addressed the vulnerability by improving checks. The flaw was reported by Michael Jimenez and an anonymous researcher. The […]<\/p>\n","protected":false},"author":1,"featured_media":116014,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3323,2624,55],"tags":[12,4112,9508,9506,1067,10918,687,841,1533],"class_list":["post-169381","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-breaking-news","category-mobile-2","category-security","tag-apple","tag-hacking","tag-hacking-news","tag-information-security-news","tag-ios","tag-it-information-security","tag-pierluigi-paganini","tag-security-affairs","tag-security-news"],"yoast_head":"\n杭州江阴科强工业胶带有限公司