iOS 14.4 Patches Vulnerabilities That May Have Been Actively Exploited

Apple today released iOS 14.4 and iPadOS 14.4, and along with a handful of minor new features, the software introduces security fixes for three vulnerabilities that may have been used in the wild.

14
According to a security support document shared by Apple, there were kernel and WebKit vulnerabilities affecting all iPhones and iPads running iOS or iPadOS 14. The kernel vulnerability could allow a malicious application to elevate privileges, and Apple says it is aware of a report that the issue may have been actively exploited.

Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.
Description: A race condition was addressed with improved locking.
CVE-2021-1782: an anonymous researcher

Apple also says a WebKit issue that allowed for a remote attacker to cause arbitrary code execution may have been actively exploited.

Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation)
Impact: A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: A logic issue was addressed with improved restrictions.
CVE-2021-1871: an anonymous researcher
CVE-2021-1870: an anonymous researcher

There is no other information available at this time, but Apple's support document says that additional information will be "available soon."

Given that significant vulnerabilities are patched in the iOS 14.4 and iPadOS 14.4 updates, those running iOS 14 should update as soon as possible.

Related Forum: iOS 14

Popular Stories

apple wallet drivers license feature iPhone 15 pro

Apple Plans to Expand iPhone Driver's Licenses to These 7 U.S. States

Thursday January 2, 2025 6:45 am PST by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Below, we outline which U.S. states and territories offer the feature, and additional states that have committed to rolling it out in...
MacBook Air 15 Inch Feature Purple

New MacBook Air Models Coming Soon With These Rumored Features

Thursday January 2, 2025 6:42 am PST by
One of Apple's first product announcements of 2025 will likely be updated 13-inch and 15-inch MacBook Air models with the M4 chip. Below, we recap rumors about the next MacBook Air models. New Features Expected The new MacBook Air models are expected to be equipped with Apple's already-released M4 chip, which has a 10-core CPU and a 10-core GPU. Apple already updated the MacBook...
iPhone 17 Slim Feature Single Camera 1 Redux

iPhone 17 Air's Thickness and Price Range Revealed in New Report

Friday January 3, 2025 7:16 am PST by
Apple is widely rumored to be planning an ultra-thin iPhone 17 model for release later this year, and a new report offers a few purported details. South Korea's Sisa Journal today reported that Apple is aiming for the so-called "iPhone 17 Air" to be 6.25mm thick. If that measurement ends up being accurate, the device would become the thinnest iPhone ever, topping the current 6.9mm record set ...
apple vision pro

Apple Vision Pro May Now Be Out of Production

Tuesday December 31, 2024 2:00 pm PST by
Apple's first-generation Vision Pro headset may have now ceased production, following reports of reduced demand and production cuts earlier in the year. In October, The Information's Wayne Ma reported that Apple had abruptly reduced production of the Vision Pro headset ahead of potential plans to stop making the current version of the device completely by the end of 2024. With the year now...
Generic iOS 18

Here's What's New in iOS 18.3 So Far

Friday January 3, 2025 11:58 am PST by
iOS 18.3 is currently in beta for developers and public beta testers. So far, the upcoming iPhone software update is very minor in scope. Below, we outline what is new in iOS 18.3 so far. The only potential new feature coming to iPhones with iOS 18.3 so far is robot vacuum support in the Home app, but this functionality is not yet live. Apple is laying the groundwork for the feature,...
iPhone SE 4 Thumb 1

'iPhone SE 4' Rumored to Be Named 'iPhone 16E'

Wednesday January 1, 2025 8:31 am PST by
Apple is expected to release a fourth-generation iPhone SE in March, but it has been rumored that the device will have a different name. The device succeeding the third-generation iPhone SE will be named the iPhone 16E, according to a December 13 post from Fixed Focus Digital, an account with over two million followers on Chinese social media platform Weibo. On December 31, another leaker...
aapl logo banner

Apple Broke a 13-Year Hardware Streak in 2024

Wednesday January 1, 2025 1:00 am PST by
For over a decade, Apple has consistently announced all-new hardware product lines, from the iPad in 2010 to the Vision Pro in 2023. But for the first time in 14 years, Apple failed to announce any major new hardware products in 2024, focusing solely on updates and refinements to its existing product lines. While Apple unveiled a large number of significant hardware refreshes in 2024, such...
Apple Intelligence General Feature

Here's What's Changing With Siri in 2025

Friday January 3, 2025 2:52 pm PST by
Apple started making Siri more capable with Apple Intelligence features in iOS 18.1 and iOS 18.2, but there are additional Siri updates that are set to come in 2025 with iOS 18 and iOS 19. By this time next year, Siri should be much smarter, if Apple's planned changes live up to what the company says is coming. Features Coming in iOS 18 The best new Siri features haven't been added yet,...

Top Rated Comments

LFC2020 Avatar
52 months ago
Great work apple, you don’t get this kind of support with android, may the walled garden continue to blossom. ???
Score: 9 Votes (Like | Disagree)
Unregistered 4U Avatar
52 months ago
The security researchers I admire? These ones:

CVE-2021-1782: an anonymous researcher
CVE-2021-1871: an anonymous researcher
CVE-2021-1870: an anonymous researcher

Never have to worry about if they’re doing it to drive business or for publicity :)
Score: 7 Votes (Like | Disagree)
fhall1 Avatar
52 months ago

Remember updating to that abortion OS called Catalina???
Nope - so far my machines are still running Mojave
Score: 6 Votes (Like | Disagree)
Apple_Robert Avatar
52 months ago
I am glad Apple is so proactive in this area.
Score: 5 Votes (Like | Disagree)
zorinlynx Avatar
52 months ago
I wonder if these holes are in iOS 12; lots of iPhone 6 users still out there, like my mom.
Score: 5 Votes (Like | Disagree)
Apple_Robert Avatar
52 months ago

And this, folks, is why one should always stay up to date.
Exactly. Too many people around here don't update their device because they afraid of performance. In my opinion, security takes precedence.
Score: 4 Votes (Like | Disagree)