苹果于9月15日发布了 iOS/iPadOS 27 的安全公告,共计修复了 126 个安全漏洞1。这些漏洞涵盖多个高风险问题,其中包括可使沙盒化应用以内核权限执行任意代码的漏洞(CVE-2026-84607)、允许应用导致系统终止或写入内核内存的漏洞(CVE-2026-84523),以及多项可造成内核内存损坏和泄露的内核漏洞(如 CVE-2026-43689)1。
此次安全更新中,中国开发者和国内安全团队做出了重要贡献1。其中包括中国开发者 Zhongcheng Li、字节跳动 IES Red Team、百度等团队参与了漏洞的发现与上报1。苹果建议用户尽快升级至最新版本以修复这些安全风险1。
Apple released a security advisory for iOS and iPadOS 27 on September 15, addressing a total of 126 security vulnerabilities 1. The update resolves numerous high-risk issues spanning kernel privilege escalation, sandbox bypasses, and remote wireless attacks 1.
Among the critical vulnerabilities patched is CVE-2026-84607 affecting AVEVideoEncoder, which could allow sandboxed applications to execute arbitrary code with kernel privileges 1. Another significant flaw, CVE-2026-84523 in APFS, could enable applications to terminate the system or write to kernel memory 1. Additional kernel vulnerabilities including CVE-2026-43689 and related issues have been remedied to prevent kernel memory corruption and information disclosure 1.
The security contributions came from multiple sources, including Chinese developer Zhongcheng Li, ByteDance's IES Red Team, Baidu, and other teams 1. Apple has advised users to update their devices promptly to mitigate the security risks addressed in this release 1.
评论
还没有评论,欢迎留下第一条。