News: 1683070243

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple pushes first-ever 'rapid' patch – and rapidly screws up

(2023/05/03)


Apple on Monday pushed to some iPhones and Macs its first-ever rapid security fix.

This type of patch is supposed to be downloaded and applied automatically and seamlessly by the operating system to immediately protect devices from exploitation, thus avoiding the usual system update cycle that users may put off or miss and thus leave their stuff vulnerable to attack.

As luck would have it, though, this first-of-its-kind patch didn't go off without a hitch. Some Cupertino fans reported [1]problems actually getting the update.

[2]

"iOS Security Response 16.4.1 (a) failed verification because you are no longer connected to the internet," was the commonly reported failure message from the operating system, although users typically were able to apply the security update after a try or two.

[3]

[4]

Also: Apple hasn't released any notes alongside the rapid patch nor if the update patched a vulnerability that miscreants have already found and exploited. And as security analyst Will Dormann [5]asked , will the bug(s) will eventually be assigned CVEs?

These Apple Rapid Security Response updates...They'll eventually get CVEs and descriptions, right? [6]pic.twitter.com/IQqT6rALLo — Will Dormann (@wdormann) [7]May 1, 2023

Considering that some recent iOS and macOS updates covered zero-days that had already been exploited by snoops to [8]deploy spyware on victims' devices, it's a good idea not to wait on installing this one latest fix, even if the installation process takes longer than it should.

Here's what we do know about the iGiant's first-ever "Rapid Security Response," according to Apple's [9]May 1 advisory :

Rapid Security Responses are a new type of software release for iPhone, iPad, and Mac. They deliver important security improvements between software updates — for example, improvements to the Safari web browser, the WebKit framework stack, or other critical system libraries. They may also be used to mitigate some security issues more quickly, such as issues that might have been exploited or reported to exist "in the wild."

Note: the quotation marks around "in the wild" are Apple's, not ours.

[10]Another zero-click Apple spyware maker just popped up on the radar again

[11]Apple squashes iOS, macOS zero-day bugs already exploited by snoops

[12]Apple, Google propose anti-stalking spec for Bluetooth tracker tags

[13]Update now: Google emits emergency fix for zero-day Chrome vulnerability

Also, Apple only pushes these new quick fixes to the latest versions of iOS, iPadOS and macOS beginning with iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1. Customers with more venerable software will have to wait for normal software updates.

These latest fixes are supposed to be applied automatically by default (assuming they work), and once the update has been verified, it's denoted by a letter after the numbers, ie: macOS 13.3.1(a).

If you turn off this default setting (probably a bad idea in the long run), your device will receive the fixes when they are included in a regular [14]OS update . ®

Get our [15]Tech Resources



[1] https://appleinsider.com/articles/23/05/01/apple-issues-rapid-security-response-update-for-ios-1641-macos-1331

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFHcZWBJMHVlUwbMP0pVVwAAAIc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFHcZWBJMHVlUwbMP0pVVwAAAIc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFHcZWBJMHVlUwbMP0pVVwAAAIc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://twitter.com/wdormann/status/1653128465699287041

[6] https://t.co/IQqT6rALLo

[7] https://twitter.com/wdormann/status/1653128465699287041?ref_src=twsrc%5Etfw

[8] https://www.theregister.com/2023/04/10/apple_fix_ios_macos/

[9] https://support.apple.com/en-us/HT201224

[10] https://www.theregister.com/2023/04/12/quadream_spyware_microsoft_citizenlab/

[11] https://www.theregister.com/2023/04/10/apple_fix_ios_macos/

[12] https://www.theregister.com/2023/05/02/apple_google_antistalking_bluetooth/

[13] https://www.theregister.com/2023/04/17/chrome_emergency_patch/

[14] https://support.apple.com/en-us/HT201222

[15] https://whitepapers.theregister.com/



Great idea ...

Anonymous Coward

... marred by confusing versioning. It's supposed to be an imitation of Android security patch levels, but the Android versioning by date is much more obvious than three point numbers and a letter.

If only the Android security patch system worked though. The outdated Android version problem that it set out to solve never got solved.

Tim99

In Oz my iMac had a message on the screen this morning suggesting that I restart it now (or later). Seems OK. Then did 2 iPad Pro's and 2 iPhones. All went well, except Mrs Tim99's iPhone which had a flat battery - Recharged to ~5%, then had to manually request patch, but needed an additional restart to avoid "Update Later" as the only choice, now OK...

If at first you fail...

chuckufarley

...fail with dignity and transparency.

If not that then just fail.

MattPi

iPhone 11 this morning. Start the patch process looked a minute later and the phone was off-off. Booted back up fine, but seems like the patch crashed the phone.

Nothing is ever a total loss; it can always serve as a bad example.