About the security content of iOS 16.7.8 and iPadOS 16.7.8 - Apple Support (2024)

This document describes the security content of iOS 16.7.8 and iPadOS 16.7.8.

About Apple security updates

For our customers' protection, Apple doesn't disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page.

Apple security documents reference vulnerabilities by CVE-ID when possible.

For more information about security, see the Apple Product Security page.

iOS 16.7.8 and iPadOS 16.7.8

Released May 13, 2024

Core Data

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to access sensitive user data

Description: An issue was addressed with improved validation of environment variables.

CVE-2024-27805: Kirin (@Pwnrin) and 小来来 (@Smi1eSEC)

Entry added June 10, 2024

CoreMedia

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved checks.

CVE-2024-27817: pattern-f (@pattern_F_) of Ant Security Light-Year Lab

Entry added June 10, 2024

CoreMedia

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: Processing a file may lead to unexpected app termination or arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved input validation.

CVE-2024-27831: Amir Bazine and Karsten König of CrowdStrike Counter Adversary Operations

Entry added June 10, 2024

Foundation

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to access user-sensitive data

Description: A logic issue was addressed with improved checks.

CVE-2024-27789: Mickey Jin (@patch1t)

IOHIDFamily

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An unprivileged app may be able to log keystrokes in other apps including those using secure input mode

Description: This issue was addressed with additional entitlement checks.

CVE-2024-27799: an anonymous researcher

Entry added June 10, 2024

Kernel

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A user may be able to cause unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved memory handling.

CVE-2024-27818: pattern-f (@pattern_F_) of Ant Security Light-Year Lab

Entry added June 10, 2024

Kernel

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An attacker that has already achieved kernel code execution may be able to bypass kernel memory protections

Description: The issue was addressed with improved memory handling.

CVE-2024-27840: an anonymous researcher

Entry added June 10, 2024

Kernel

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An attacker in a privileged network position may be able to spoof network packets

Description: A race condition was addressed with improved locking.

CVE-2024-27823: Prof. Benny Pinkas of Bar-Ilan University, Prof. Amit Klein of Hebrew University, and EP

Entry added July 29, 2024

Mail

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An attacker with physical access may be able to leak Mail account credentials

Description: An authentication issue was addressed with improved state management.

CVE-2024-23251: Gil Pedersen

Entry added June 10, 2024

Mail

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A maliciously crafted email may be able to initiate FaceTime calls without user authorization

Description: The issue was addressed with improved checks.

CVE-2024-23282: Dohyun Lee (@l33d0hyun)

Entry added June 10, 2024

Messages

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: Processing a maliciously crafted message may lead to a denial-of-service

Description: This issue was addressed by removing the vulnerable code.

CVE-2024-27800: Daniel Zajork and Joshua Zajork

Entry added June 10, 2024

Metal

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution

Description: An out-of-bounds read was addressed with improved input validation.

CVE-2024-27802: Meysam Firouzi (@R00tkitsmm) working with Trend Micro Zero Day Initiative

Entry added June 10, 2024

RTKit

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An attacker with arbitrary kernel read and write capability may be able to bypass kernel memory protections. Apple is aware of a report that this issue may have been exploited.

Description: A memory corruption issue was addressed with improved validation.

CVE-2024-23296

Shortcuts

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user

Description: The issue was addressed with improved checks.

CVE-2024-27855: an anonymous researcher

Entry added June 10, 2024

Spotlight

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to access sensitive user data

Description: This issue was addressed with improved environment sanitization.

CVE-2024-27806

Entry added June 10, 2024

Symptom Framework

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to circumvent App Privacy Report logging

Description: The issue was addressed with improved checks.

CVE-2024-27807: Romy R.

Entry added June 10, 2024

Sync Services

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved checks

CVE-2024-27847: Mickey Jin (@patch1t)

Entry added June 10, 2024

Voice Control

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A user may be able to elevate privileges

Description: The issue was addressed with improved checks.

CVE-2024-27796: ajajfxhj

Entry added June 10, 2024

WebKit

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A maliciously crafted webpage may be able to fingerprint the user

Description: The issue was addressed by adding additional logic.

WebKit Bugzilla: 262337

CVE-2024-27838: Emilio Cobos of Mozilla

Entry added June 10, 2024

WebKit

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: Processing maliciously crafted web content may lead to arbitrary code execution

Description: An integer overflow was addressed with improved input validation.

WebKit Bugzilla: 271491

CVE-2024-27833: Manfred Paul (@_manfp) working with Trend Micro Zero Day Initiative

Entry added June 10, 2024

WebKit

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication

Description: The issue was addressed with improved checks.

WebKit Bugzilla: 272750

CVE-2024-27834: Manfred Paul (@_manfp) working with Trend Micro's Zero Day Initiative

Entry added June 10, 2024

WebKit Web Inspector

Available for: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation

Impact: Processing web content may lead to arbitrary code execution

Description: The issue was addressed with improved memory handling.

WebKit Bugzilla: 270139

CVE-2024-27820: Jeff Johnson of underpassapp.com

Entry added June 10, 2024

Information about products not manufactured by Apple, or independent websites not controlled or tested by Apple, is provided without recommendation or endorsem*nt. Apple assumes no responsibility with regard to the selection, performance, or use of third-party websites or products. Apple makes no representations regarding third-party website accuracy or reliability. Contact the vendor for additional information.

Published Date:

About the security content of iOS 16.7.8 and iPadOS 16.7.8 - Apple Support (2024)

FAQs

Is the iOS 16.7 update safe? ›

iOS 16.7.

This update provides important security fixes and is recommended for all users.

What is the iOS 16.7.8 update? ›

The iOS 16.7. 8 and iPadOS 16.7. 8 update is releasing alongside the iOS 17.5 for newer Apple iPhones. The latest version of iOS comes with features such as cross-platform tracking detection, improved third-party app support in EU, offline support for Apple News and more.

What is iPadOS 16 security update? ›

This update includes the following enhancements and bug fixes: Security Keys for Apple ID allow users to strengthen the security of their account by requiring a physical security key as part of the two factor authentication sign in process on new devices. Support for HomePod (2nd generation)

What does iOS 16.7 fix? ›

iOS 16.7.

This update addresses an issue that prevents enabling or disabling Advanced Data Protection.

Is iOS 16 safe from hackers? ›

Safety Check and Lockdown Mode give people in vulnerable situations ways to quarantine themselves from acute risks. Apple has long said that it offers software that is secure and private enough for all users by default, without special tiers or paid services.

Is iOS 16 causing problems? ›

iOS 16.0.

Camera may vibrate and cause blurry photos when shooting with some third-party apps on iPhone 14 Pro and iPhone 14 Pro Max. Display may appear completely black during device setup. Copy and paste between apps may cause a permission prompt to appear more than expected. VoiceOver may be unavailable after ...

How long will iOS 16 be supported? ›

Apple iOS
ReleaseReleasedActive Support
1711 months ago (18 Sep 2023)Yes
161 year and 11 months ago (12 Sep 2022)Ended 11 months ago (18 Sep 2023)
152 years and 11 months ago (20 Sep 2021)Ended 1 year and 11 months ago (12 Sep 2022)
143 years and 11 months ago (16 Sep 2020)Ended 2 years and 11 months ago (20 Sep 2021)
10 more rows
Aug 8, 2024

What is the latest iOS version? ›

iOS 17 is the newest version of iOS, the operating system that is designed to run on the iPhone. Previewed in June, iOS 17 is available now on the iPhone XR/XS and later.

Which iOS 16 is latest? ›

iOS 16
iOS 16 home screen on an iPhone 14 Pro
DeveloperApple
General availabilitySeptember 12, 2022
Latest release16.7.10 (August 7, 2024) [±]
Support status
11 more rows

Which iPads can no longer be updated? ›

These devices aren't made anymore and don't support the latest versions of iPadOS.
  • iPad: Original, 2, 3, 4.
  • iPad Air: Original.
  • iPad Mini: Original, 2, 3.
May 15, 2024

Are those Apple virus warnings real? ›

Is the Apple Security Alert Real? If you're seeing pop-up messages warning you of security alerts or virus attacks against your Apple device, you're most likely worried. But while these messages may look real, they're almost certainly scams.

Is iOS 16 safe to install now? ›

For now, you are fairly safe—Apple will continue supporting and updating iOS 16 for at least a couple more months.

How long does iOS 16.7 take to install? ›

Part 1: How Long Does iOS 16/17 Update Take?
Sync(Optional)Backup & Transfer(Optional)iOS 16/17 Installation
5-45 Min1-30 Min10-20 Min
Jul 29, 2024

Why do I keep getting an error when trying to install iOS 16? ›

If you can't install the latest version of iOS or iPadOS on your iPhone or iPad. You might be unable to update your iPhone or iPad wirelessly, or over the air, for one of these reasons: Your device doesn't support the latest software. There isn't enough available storage space on your device.

Is the new iOS update safe? ›

Apple's latest iPhone upgrade fixes important bugs and could include security updates, so it's good idea to update to iOS 17.6.1 now. Go to your Settings > General > Software Update and upgrade to iOS 17.6.1 as soon as you can.

Is it ok to update to iOS 16 now? ›

iOS 16.0.

This update is recommended for all iPhone 14 and iPhone 14 Pro users and provides important bug fixes including the following: iMessage and FaceTime may not complete activation.

Is iOS 16 safe to download now? ›

It is safe to update to iOS 16! In fact, it since has been updated again to 16.1. It's necessary to update to the latest iOS every time a new one is released!

When did 16.7 come out? ›

Release history
VersionBuildRelease date
16.720H19September 21, 2023
16.7.120H30October 10, 2023
16.7.220H115October 25, 2023
16.7.320H232December 11, 2023
26 more rows

References

Top Articles
CEST to GMT Converter - Savvy Time
CEST to Amsterdam, Netherlands - Savvy Time
Wsbtv Fish And Game Report
Irela Torres Only Fans
Mychart.texaschildrens.org.mychart/Billing/Guest Pay
Umc Webmail
Evo Unblocked
Myud Dbq
Clarita Amish Auction 2023
Hillsborough County Florida Recorder Of Deeds
J. Foster Phillips Funeral Home Obituaries
Stanford Rival Crossword Clue
Vector Driver Setup
Cheap Motorcycles For Sale Under 1000 Craigslist Near Me
Karz Insurance Quote
5 takeaways from Baylor’s historic comeback win vs. UCF: Bears find new energy in Orlando
Dr. Katrina (Katrina Hutchins) on LinkedIn: #dreambig #classof2025 #bestclassever #leadershipaugusta
C.J. Stroud und Bryce Young: Zwei völlig unterschiedliche Geschichten
Odawa Hypixel
Appraisalport Com Dashboard /# Orders
Winta Zesu Net Worth
Az511 Twitter
Minor-Morris Recent Obituaries
Alyssa Edwards looks back, back, back again on her best 'Drag Race' moments
Southern Food Buffet Near Me
Drive Mad Yandex
Owyhee County Extension Office
Southland Goldendoodles
One Person Dead In East Charlotte - WCCB Charlotte's CW
Texas Motors Specialty Photos
Craigs List Ocala
Laurin Funeral Home
Psalm 136 Nkjv
Dallas College Radiology Packet
Theatervoorstellingen in Roosendaal, het complete aanbod.
Arcane Stitch Divinity 2
Krua Thai In Ravenna
Tattered Paws And Golden Hearts Rescue
Swissport Timecard
When His Eyes Opened Chapter 3021
Currently Confined Coles County
Its Arrival May Be Signaled By A Ding
Ekaterina Lisina Wiki
Abq Pets Craigslist
Welcome to Predator Masters -- Hunting the Hunters
Potomac Edison Wv Outages
Veronika Sherstyuk Height
Stephen Dilbeck Obituary
Battlenet We Couldn't Verify Your Account With That Information
Skip The Games Buffalo
Fintechzoommortgagecalculator.live Hours
Deciphering The "sydneylint Leaked" Conundrum
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6336

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.