Update to iOS 14.2 now — Apple issues emergency iPhone security update
Google finds three zero-day flaws under active attack; iPads also affected
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
Apple has pushed out an emergency update to iOS, patching three "zero-day" security flaws that are already being used by hackers to attack iPhone, iPads and iPods. Your iDevices need to be updated to iOS 14.2 and iPadOS 14.2.
"Apple is aware of reports that an exploit for this issue exists in the wild," the company says next to the description of each flaw in an Apple security advisory released today (Nov. 5).
- Best iPhones: Which iPhone should you buy?
- Why Apple iPhones don't need antivirus software
- iPhone 12 vs. iPhone 12 Pro: What's the difference?
Apple didn't call these "zero-day" flaws, but that's what they are — vulnerabilities that are attacked by hackers before the defenders have a chance to fix them.
The flaws affect the iOS/iPadOS font parser and the iOS/iPadOS kernel. The font-parser flaw "may lead to arbitrary code execution" — i.e., a hack — when "processing a maliciously crafted font," says Apple's advisory.
In the case of the second flaw, "a malicious application may be able to disclose kernel memory," which would expose passwords, keychains and other sensitive data.
The third flaw would let "a malicious application ... execute arbitrary code with kernel privileges," which is pretty much full system takeover.
The updates to iOS and iPadOS 14.2 fix 21 other security flaws, none of which are under active attack.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
Apple also upgraded iOS 12 to version 12.4.9 to fix the three zero-day flaws plus one older FaceTime flaw on devices that can't run iOS 14, including the iPhone 5s, 6 and 6 Plus, plus the iPad Air, iPad mini 2, iPad mini 3 and 6th-generation iPod touch.
- Can a free iPhone VPN match up to a paid iPhone VPN?
Who's attacking what?
Reading between the lines, we get the fuzzy outlines of a multi-stage attack chaining together these three actively exploited flaws.
First, use the font-parser flaw to remotely install a malicious app via a webpage; then use the malicious app and one kernel flaw to steal passwords; third, use the malicious app and the other kernel flaw to install even more malware.
And that sounds like a state-sponsored attack against specifically selected targets. China, for example, has used similar attacks on both iOS and Android devices to spy on ethnic Tibetan and Uyghur dissidents.
Criminal groups just out for money could also pull this sort of thing off, but they usually find it more profitable to stick to phishing attacks, adware and other low-hanging fruit.
These three flaws were discovered by the very busy researchers at Google Project Zero, whose technical lead Ben Hawkes disclosed them on Twitter.
Apple have fixed three issues reported by Project Zero that were being actively exploited in the wild. CVE-2020-27930 (RCE), CVE-2020-27950 (memory leak), and CVE-2020-27932 (kernel privilege escalation). The security bulletin is available here: https://t.co/4OIReajIp6November 5, 2020
Project Zero researchers in the past couple of weeks have also uncovered two zero-day flaws in Chrome and Chromium-based browsers and one zero-day flaw in Windows.
All these flaws are also being actively exploited. The Windows one hasn't been patched yet, but it won't work without one of the Chrome flaws, both of which have been fixed with browser updates.

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.
