https://techcrunch.com/2025/01/28/apple-fixes-zero-day-flaw-affecting-all-devices/ [tc-lockup] TechCrunch Desktop Logo [tc-lo] TechCrunch Mobile Logo * Latest * Startups * Venture * Apple * Security * AI * Apps * Events * Podcasts * Newsletters Sign In Search [ ]Submit * Site Search Toggle Mega Menu Toggle Topics Latest AI Amazon Apps Biotech & Health Climate Cloud Computing Commerce Crypto Enterprise EVs Fintech Fundraising Gadgets Gaming Google Government & Policy Hardware Instagram Layoffs Media & Entertainment Meta Microsoft Privacy Robotics Security Social Space Startups TikTok Transportation Venture More from TechCrunch Events Startup Battlefield StrictlyVC Newsletters Podcasts Videos Partner Content TechCrunch Brand Studio Crunchboard Contact Us Sign In MacBook pro 2021 half open with Iphone 13 lit by retina displayImage Credits:Wirestock / Getty Images Security Apple fixes zero-day flaw affecting all devices Lorenzo Franceschi-Bicchierai 8:20 AM PST * January 28, 2025 Apple released the latest updates for its iPhone, iPad, and Mac operating systems on Monday, which included switching on Apple Intelligence by default for newer devices. As part of this batch of software updates, Apple also released several patches fixing security bugs, including a zero-day bug that "may have been actively exploited" -- meaning hackers were using it to compromise devices -- against users with iPhones running software older than iOS 17.2, which was released in December 2023. The bug was found in Core Media, the media engine that powers a range of Apple devices, and is now fixed across its product line, including iPhones, iPads, Macs, Apple TVs, Apple Watches, and its mixed-reality headset, Vision Pro. Apple said hackers could have "elevated privileges" by exploiting a memory corruption bug, which would have allowed broader access to a device's data. Apple did not credit the bug discovery to any researcher, as it customarily -- but not always -- does. A spokesperson for Apple did not immediately comment when asked for more details about who exploited the bug and against whom. This is the first bug found in iOS this year that was exploited in the wild. For reference, Apple fixed at least seven bugs that "may have been actively exploited" in 2024, according to TechCrunch's running tally. Topics Apple, cybersecurity, hackers, hacking, infosec, iOS, iPad, iPhone, Security, Zero-days Lorenzo Franceschi-Bicchierai Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy. You can contact Lorenzo securely on Signal at +1 917 257 1382, on Keybase/ Telegram @lorenzofb, or via email at lorenzo@techcrunch.com. View Bio Most Popular * Apple fixes zero-day flaw affecting all devices + Lorenzo Franceschi-Bicchierai * Google Maps will soon rename Gulf of Mexico to 'Gulf of America' + Maxwell Zeff * Former Intel CEO Pat Gelsinger is already using DeepSeek instead of OpenAI at his startup, Gloo + Julie Bort * DeepSeek claims its 'reasoning' model beats OpenAI's o1 on certain benchmarks + Kyle Wiggers * Viral AI company DeepSeek releases new image model family + Kyle Wiggers * Meta AI can now use your Facebook and Instagram data to personalize its responses + Kyle Wiggers * DeepSeek 'punctures' AI leaders' spending plans, and what analysts are saying + Manish Singh Newsletters See More Subscribe for the industry's biggest tech news TechCrunch Daily News Every weekday and Sunday, you can get the best of TechCrunch's coverage. TechCrunch AI TechCrunch's AI experts cover the latest news in the fast-moving field. TechCrunch Space Every Monday, gets you up to speed on the latest advances in aerospace. Startups Weekly Startups are the core of TechCrunch, so get our best coverage delivered weekly. No newsletters selected. [ ] Subscribe By submitting your email, you agree to our Terms and Privacy Notice. Related * DeepSeek app icon on mobile phone AI DeepSeek triggered a wild, baseless rally for some Chinese stocks + Charles Rollet 59 minutes ago * DeepSeek app In Brief Who is Liang Wenfeng? DeepSeek founder comes from AI investing + Amanda Silberling 4 hours ago * ChatGPT welcome screen AI ChatGPT: Everything you need to know about the AI-powered chatbot + Kyle Wiggers + Cody Corrall + Alyssa Stringer 6 hours ago Latest in Security See More * MacBook pro 2021 half open with Iphone 13 lit by retina display Security Apple fixes zero-day flaw affecting all devices + Lorenzo Franceschi-Bicchierai 7 hours ago * a laptop in a dark room with the laptop keyboard lit up with a red and blue glitchy effect, and the display reads PowerSchool with its corporate logo. Security PowerSchool begins notifying students and teachers after massive data breach + Carly Page 8 hours ago * [GettyImages-2170386424] In Brief OpenAI launches ChatGPT plan for US government agencies + Kyle Wiggers 8 hours ago TechCrunch Logo * X * LinkedIn * Facebook * Instagram * youTube * Mastodon * Threads * Bluesky * TechCrunch * Staff * Contact Us * Advertise * Crunchboard Jobs * Site Map * Terms of Service * Privacy Policy * RSS Terms of Use * Privacy Placeholder 1 * Privacy Placeholder 2 * Privacy Placeholder 3 * Privacy Placeholder 4 * Code of Conduct * About Our Ads * DeepSeek * Liang Wenfeng * Waymo In LA * Openvibe * Bluesky * Tech Layoffs * ChatGPT (c) 2024 Yahoo.