iOS 14.8 and iPadOS 14.8 With Security Updates Now Available

iOS 14.8 and iPadOS 14.8 With Security Updates Now Available

Apple today released iOS 14.8, which is a security-centric update offering two fixes for zero-day exploits. iOS 14.8 is the eighth major update to the iOS operating system. The new update comes two months after the iOS 14.7 update.

Apple has also released an update for iPadOS, as well as watchOS 7.6.2, which includes similar security fixes for Apple Watch Series 3 and later.

The iOS 14.8 update is available as an over-the-air update on eligible devices, in the Settings app. To access the new software, go to “Settings” -> “General” -> “Software Update.

Apple’s release notes say iOS 14.8 is a security-focused update that is recommended for all users. An Apple security support document outlines two major security fixes that have been put in place for issues that Apple says may have already been actively exploited.

iOS 14.8 and iPadOS 14.8

Released September 13, 2021

CoreGraphics

Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

Impact: Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Description: An integer overflow was addressed with improved input validation.

CVE-2021-30860: The Citizen Lab

WebKit

Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Description: A use after free issue was addressed with improved memory management.

CVE-2021-30858: an anonymous researcher