Cyber Security

Apple iTunes For Windows Flaw Let Attackers Execute Malicious Code

A new arbitrary code execution vulnerability has been discovered in iTunes that could allow a threat actor to perform malicious activities.

This vulnerability has been assigned with CVE-2024-27793 and the severity is yet to be categorized.

Apple has released a security advisory for addressing this vulnerability which also specified that “Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available”

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

Technical Analysis

According to the reports shared with Cyber Security News, this vulnerability exists in iTunes version prior to 12.13.1 for Windows which could allow parsing a malicious file which may lead to unexpected app termination or arbitrary code execution on the affected device. 

However, Apple has addressed this vulnerability by improving checks before parsing a malicious file.

Users of Apple iTunes for Windows are recommended to upgrade to iTunes version 12.13.2 for patching this vulnerability.

In recent times, there have been several vulnerabilities being identified in Apple in which the most recent one was the SQL injection vulnerability that led to hacking the infrastructure of Apple.

Some of the interesting cases of Apple products being targeted by threat actors are “push bombing” attacks, GoFetch vulnerability exploitation, a type confusion zero-day (CVE-2024-23222) and several others.

Additionally, there were also cases where Apple’s iMessage was exploited. It is recommended for users of Apple products to upgrade their devices to the latest versions in order to prevent these kinds of vulnerabilities getting exploited by threat actors.

On-Demand Webinar to Secure the Top 3 SME Attack Vectors: Watch for Free

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago