<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebKit瀏覽器引擎零時差漏洞 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/webkit%e7%80%8f%e8%a6%bd%e5%99%a8%e5%bc%95%e6%93%8e%e9%9b%b6%e6%99%82%e5%b7%ae%e6%bc%8f%e6%b4%9e/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Thu, 13 Apr 2023 06:05:12 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>WebKit瀏覽器引擎零時差漏洞 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Apple發布安全更新　修復舊款iPhone和iPad零時差漏洞</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/44184/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/44184/#respond</comments>
		
		<dc:creator><![CDATA[科技新知]]></dc:creator>
		<pubDate>Tue, 28 Mar 2023 08:18:08 +0000</pubDate>
				<category><![CDATA[3C]]></category>
		<category><![CDATA[資安]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[WebKit瀏覽器引擎零時差漏洞]]></category>
		<category><![CDATA[安全漏洞]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=44184</guid>

					<description><![CDATA[<p><img width="1200" height="627" src="https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="156969980 fb link normal none" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none.jpg 1200w, https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none-300x157.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none-1024x535.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none-768x401.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Apple發布安全更新　修復舊款&lt;a&gt;&lt;/a&gt;iPhone和iPad零時差漏洞 4"></p>
<p>編譯／鄭智懷 Apple在美西當地時間27日發布iOS 15.7.4 和 iPadOS 15.7.4更新內容， &#8230;<content><!-- wp:paragraph --></p>
<p>編譯／鄭智懷</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Apple在美西當地時間27日發布iOS 15.7.4 和 iPadOS 15.7.4更新內容，以解決多起系統錯誤或安全漏洞，其中包含一項已被駭客廣泛利用的WebKit瀏覽器引擎零時差漏洞。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>根據Apple公告，該項由匿名研究員通報的零時差漏洞被命名為「CVE-2023-23529」。而本次發布的補丁主要針對iPhone 6s（所有型號）、iPhone 7（所有型號）、iPhone SE（第1代）、iPad Air 2、iPad mini（第4代）和 iPod touch（第7代）。至於在較新版本的iPhone 和 iPad中的相同漏洞，Apple早在2月13日已經透過檢查與改進，並釋出補丁修補相關問題。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:image {"id":44185,"sizeSlug":"large","linkDestination":"none"} --></p>
<figure class="wp-block-image size-large"><img src="https://www.technice.com.tw/wp-content/uploads/2023/03/156969980_fb-link_normal_none-1024x535.jpg" alt="" class="wp-image-44185"/><figcaption class="wp-element-caption">根據Apple公告，該項由匿名研究員通報的零時差漏洞被命名為「CVE-2023-23529」。而本次發布的補丁主要針對iPhone 6s（所有型號）、iPhone 7（所有型號）、iPhone SE（第1代）、iPad Air 2、iPad mini（第4代）和 iPod touch（第7代）。示意圖:RF123</figcaption></figure>
<p><!-- /wp:image --></p>
<p><!-- wp:paragraph --></p>
<p>美國網路安全暨基礎設施安全局（CISA）則在2 月 14 日將「CVE-2023-23529」列入其已知安全漏洞資料庫之中。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>在技術方面，Apple指出「CVE-2023-23529」會導致受害者打開惡意網頁後，網路犯罪者可以藉此入侵前者iPhone 和iPad並執行任意程式碼，進而使設備系統崩潰。事實上，該安全漏洞還會影響macOS Big Sur作業系統和Monterey上的Safari 16.3.1瀏覽器。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>儘管Apple在公告中表示知道駭客廣泛利用「CVE-2023-23529」攻擊名下產品的現象；但基於其旨在限制技術細節流出，減緩攻擊者開發和使用針對性攻擊手法的考量所訂下的公司政策，除了上述相關的訊息，Apple並未提供更進一步的說明。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>根據現有資訊，專家指出利用「CVE-2023-23529」所發起的攻擊活動具強烈的針對性，並非所有人都會受到威脅；但是，仍然建議盡快安裝Apple最新釋出的安全更新，以杜絕駭客鎖定舊款iPhone 和iPad運行舊版軟體的潛在漏洞而遂行的網路攻擊行動。</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>資料來源：<a href="https://support.apple.com/en-us/HT213673#:~:text=CVE%2D2023%2D23529%3A%20an%20anonymous%20researcher">Apple</a>、<a href="https://www.bleepingcomputer.com/news/apple/apple-fixes-recently-disclosed-webkit-zero-day-on-older-iphones/">BleepingComputer</a>、<a href="https://securityaffairs.com/144114/hacking/cve-2023-23529-apple-zero-day.html">Security Affairs</a></p>
<p><!-- /wp:paragraph --></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/44184/">Apple發布安全更新　修復舊款&lt;a&gt;&lt;/a&gt;iPhone和iPad零時差漏洞</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/44184/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
