{"id":1212,"date":"2025-04-02T04:43:12","date_gmt":"2025-04-02T04:43:12","guid":{"rendered":"https:\/\/www.europesays.com\/uk\/1212\/"},"modified":"2025-04-02T04:43:12","modified_gmt":"2025-04-02T04:43:12","slug":"ios-18-4-update-now-warning-issued-to-all-iphone-users","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/uk\/1212\/","title":{"rendered":"iOS 18.4\u2014Update Now Warning Issued To All iPhone Users"},"content":{"rendered":"<p class=\"color-body light-text\" role=\"button\">Apple&#8217;s iOS 18.4 update also comes with a warning to update now, because it fixes a hefty list of 60 &#8230; More security vulnerabilities, some of which are serious.<\/p>\n<p>Apple iPhone<\/p>\n<p>Update, April. 01, 2025: This story, originally published Mar. 31, now includes additional expert analysis on the flaws fixed iOS 18.4, as well as details about the other updates issued by Apple.<\/p>\n<p>Apple has issued iOS 18.4, along with a number of cool new iPhone features. But the <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/02\/25\/ios-184-the-iphone-passwords-app-just-got-a-cool-new-feature\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/02\/25\/ios-184-the-iphone-passwords-app-just-got-a-cool-new-feature\/\" target=\"_self\" aria-label=\"iOS 18.4 update\" rel=\"noopener\">iOS 18.4 update<\/a> also comes with a warning to update now, because it fixes a hefty list of 62 security vulnerabilities, some of which are serious.<\/p>\n<p>Apple doesn\u2019t give much detail about what\u2019s fixed in iOS 18.4, to give people as much time to update their iPhones as possible before attackers can get hold of the details. Among the fixes, the iOS 18.4 upgrade patches several critical bugs in WebKit, the engine that underpins the Safari browser \u2014 and the Kernel at the heart of the iPhone operating system.<\/p>\n<p>Apple\u2019s iOS 18.4 patches an issue in the iPhone Kernel tracked as tracked as CVE-2025-30432, that could see a malicious app able to attempt passcode entries on a locked device and cause escalating time delays after four failures.<\/p>\n<p>Tracked as CVE-2025-24208, a bug in WebKit could put you at risk from a <a href=\"https:\/\/owasp.org\/www-community\/attacks\/xss\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/owasp.org\/www-community\/attacks\/xss\/\" aria-label=\"cross-site scripting attack\">cross-site scripting attack<\/a> \u2014 where an attacker injects malicious scripts into a trusted website \u2014 if you inadvertently<strong> <\/strong>load a malicious iframe, Apple warns on its <a href=\"https:\/\/support.apple.com\/en-gb\/122371\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.apple.com\/en-gb\/122371\" aria-label=\"support page\">support page<\/a>.<\/p>\n<p>The iOS 18.4 patches come less than a month after Apple\u2019s emergency iPhone update <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/03\/13\/ios-1832-update-now-warning-issued-to-all-iphone-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/03\/13\/ios-1832-update-now-warning-issued-to-all-iphone-users\/\" target=\"_self\" aria-label=\"18.3.2\" rel=\"noopener\">18.3.2<\/a>, which fixed a flaw already being used in <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/03\/14\/ios-1832-deadline-you-have-19-days-to-update-your-iphone\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/03\/14\/ios-1832-deadline-you-have-19-days-to-update-your-iphone\/\" target=\"_self\" aria-label=\"real-life attacks\" rel=\"noopener\">real-life attacks<\/a>.<\/p>\n<p>Breaking Down The Bugs Squashed In iOS 18.4<\/p>\n<p>A significant number of the vulnerabilities fixed in iOS 18.4 were in WebKit. This shows that attackers continue to focus on exploiting the framework that downloads and presents web-based content, says Adam Boynton, senior security strategy manager EMEIA at Jamf.<\/p>\n<p>Another key iOS 18.4 fix is in the Kernel, which is \u201ccrucial\u201d because it manages all operating system operations and hardware interactions on your iPhone, says Boynton. He points out that the bug fixed in iOS 18.4 is worrying, because it \u201callows an attacker to attempt passcode entries despite the device being locked.\u201d<\/p>\n<p>The iOS 18.4 update also addresses vulnerabilities in Apple\u2019s Core Media. This framework is commonly used to process media, supporting a broad set of apps and managing data queues in memory, says Boynton. \u201cBy targeting these vulnerabilities, attackers can corrupt process memory and access sensitive information,\u201d he warns.<\/p>\n<p>While Apple hasn\u2019t mentioned any instances of these vulnerabilities being exploited in real attacks, the CVEs are now public, Boynton says. \u201cAttackers will likely target devices that have yet to be updated, so downloading iOS 18.4 is essential for all users.\u201d<\/p>\n<p>Apple Issues iPadOS 17.7.6, iOS 16.7.11 And iOS 15.8.4<\/p>\n<p>Alongside iOS 18.4, Apple has issued <a href=\"https:\/\/support.apple.com\/en-gb\/122372\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.apple.com\/en-gb\/122372\" aria-label=\"iPadOS 17.7.6\">iPadOS 17.7.6<\/a> for older devices the iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation. The update fixes a number of flaws, the most notable being an issue in CoreMedia that could allow a malicious application to elevate privileges, tracked as CVE-2025-24085. \u201cApple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2,\u201d the iPhone maker warns.<\/p>\n<p>Meanwhile, iOS 16.7.11 for the iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation fixes two issues used in real life attacks.<\/p>\n<p>Lastly, Apple has squashed the same bugs for very old devices in iOS 15.8.4.<\/p>\n<p>Other Updates Released By Apple<\/p>\n<p>Alongside iOS 18.4 and the updates for older iPhones and iPads, Apple released Safari 18.4 for macOS Ventura and macOS Sonoma, Xcode 16.3 for macOS Sequoia 15.2 and later, macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5. It also issued tvOS 18.4 and visionOS 2.4 for its mixed reality headset.<\/p>\n<p>Why You Should Update To iOS 18.4 Now<\/p>\n<p>Apple\u2019s iOS 18.4 fixes more than 60 issues \u2014 one of the biggest list of patches I\u2019ve seen from the iPhone maker in recent times. \u201cWith such a high number of security fixes, we strongly recommend that users update their devices to iOS 18.4,\u201d says Boynton.<\/p>\n<p>Indeed, iOS 18.4 and the other upgrades issued alongside it include important security updates for your iPhone \u2014 some of which have been used in real-life <a href=\"https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/02\/12\/ios-1831-update-now-warning-issued-to-all-iphone-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/kateoflahertyuk\/2025\/02\/12\/ios-1831-update-now-warning-issued-to-all-iphone-users\/\" target=\"_self\" aria-label=\"attacks\" rel=\"noopener\">attacks<\/a>. \u201cThese vulnerabilities could potentially allow malicious code to run on affected devices, putting data at risk as well as the device itself at risk of a remote denial of service attack,\u201d says Jake Moore, global cybersecurity advisor at ESET.<\/p>\n<p>He recommends all users install the iOS 18.4 update \u201cas soon as possible to ensure devices remain protected against these known threats.\u201d<\/p>\n<p>I agree. Apple\u2019s iOS 18.4 includes a long list of patched flaws, so it\u2019s a good idea to apply it now. Go to your Settings &gt; General &gt; Software Update and download and install iOS 18.4 now to keep your iPhone safe.<\/p>\n","protected":false},"excerpt":{"rendered":"Apple&#8217;s iOS 18.4 update also comes with a warning to update now, because it fixes a hefty list&hellip;\n","protected":false},"author":2,"featured_media":1213,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[825,834,833,831,827,829,826,828,832,830,53,16,15],"class_list":{"0":"post-1212","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"tag-apple-ios-18-4","9":"tag-apple-news","10":"tag-ios-16-7-11","11":"tag-ios-18-4-bugs","12":"tag-ios-18-4-should-i-update","13":"tag-ios-18-4-should-i-upgrade","14":"tag-ios-18-4-update","15":"tag-ios-18-4-upgrade","16":"tag-ipados-17-7-6","17":"tag-is-ios-18-4-safe","18":"tag-technology","19":"tag-uk","20":"tag-united-kingdom"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@uk\/114266544776113822","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/comments?post=1212"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/posts\/1212\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media\/1213"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/media?parent=1212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/categories?post=1212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/uk\/wp-json\/wp\/v2\/tags?post=1212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}