Is this update about iOS or OS-X?

As stated on the Apple webpage;



macOS Monterey 12.6.7



Released June 21, 2023



Kernel



Available for: macOS Monterey



Impact: An app may be able to execute

arbitrary code with kernel privileges. Apple is aware of a report that

this issue may have been actively exploited against versions of iOS

released before iOS 15.7.


Description: An integer overflow was addressed with improved input validation.



CVE-2023-32434: Georgy Kucherin (@kucher1n), Leonid Bezvershenko (@bzvr_), and Boris Larin (@oct0xor) of Kaspersky



 




Information

about products not manufactured by Apple, or independent websites not

controlled or tested by Apple, is provided without recommendation or

endorsement. Apple assumes no responsibility with regard to the

selection, performance, or use of third-party websites or products.

Apple makes no representations regarding third-party website accuracy or

reliability. Contact the vendor for additional information.




Published Date: June 21, 2023


Is this about iOS or OS-X?

THOMAS’s Mac mini

Posted on Jul 23, 2023 8:29 AM

Reply
Question marked as Top-ranking reply

Posted on Jul 23, 2023 10:31 AM

It states it is for Monterey which is the Mac OS. iOS is for iPhones and iPads, etc.

14 replies

Jul 23, 2023 3:41 PM in response to Ikearat

To answer your question, that specific page addresses Mac OS.


The vulnerability CVE-2023-32434 has been addressed in all OS versions. These updates were released before the public release of CVE-2023-32434 and is why users should keep their devices updated including the newly introduced Rapid Security updates. This is clarified here:

An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Big Sur 11.7.8, macOS Monterey 12.6.7, macOS Ventura 13.4.1, watchOS 9.5.2. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

https://nvd.nist.gov/vuln/detail/CVE-2023-32434

Jul 23, 2023 5:01 PM in response to Ikearat

OK. Several points:


  1. Mac OS X and macOS are two names for one line of Macintosh operating systems. Mac OS X 10.0 (Cheetah) through Mac OS X 10.11 (El Capitain) have OS X names. macOS 10.12 (Sierra) through macOS 13 (Ventura) – and beyond – have macOS names.
  2. Mac OS X and macOS have Unix / Mach underpinnings and enforce separation of memory between unrelated processes, unlike versions of Classic macOS (Macintosh System Software – Mac OS 9.2), where any program with a bug could scribble over memory used by other programs or the OS, and crash the entire system.
  3. Apple kept the "10" in the name all the way from Mac OS X 10.0 (Cheetah) through macOS 10.15 (Catalina). It wasn't until macOS 11 (Big Sur) that they moved on. Kind of like how when Intel came out with the "Pentium" (they apparently didn't like it that AMD could also use numbers like 486), and then released more generations of chips, called things like "Pentium II" (5 2) or "Pentium III" (5 3).
  4. "Mac OS X 10.whatever" seems redundant, as X is the Roman numeral for 10. (10 10? Deal with it.)
  5. iOS / iPadOS and all of its variants share a lot of code and technology with Mac OS X / macOS.
  6. When someone finds security vulnerabilities in one system ("versions of iOS released before iOS 15.7)"), that may indicate security vulnerabilities in other systems that use the same code/technology, or pieces of it, such as macOS.
  7. So when an Apple security alert about a macOS Monterey patch says that Apple is aware of reports that the security hole in question may have been exploited in "versions of iOS released before iOS 15.7", that's telling you that the security hole is likely in common code, and thus is potentially exploitable in macOS, too.
  8. The text that "Mac Jim ID" posted ("This issue is fixed in watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Big Sur 11.7.8, macOS Monterey 12.6.7, macOS Ventura 13.4.1, watchOS 9.5.2.") suggests the extent to which there is code sharing, of one form or another, between macOS (OS X), iOS / iPadOS, and watchOS. A report of a vulnerability in one place led to it being patched in multiple places.

Jul 23, 2023 3:29 PM in response to Ikearat

Would someone please address the issue instead of schooling me on terminology?


But terminology is central to your question, which was essentially "is this update for this operating system or that operating system".


Different Apple products run different operating systems. macOS is for Macs. Apple has not used the "OS X" terminology for about seven years. The X moniker, having supplanted the previous "Classic" Mac OS version number 9, ran its course.


Apple used to call mobile device operating systems "iOS" for their handheld devices but they don't even do that any more, having since bifurcated it into iPadOS and iPhoneOS. Then there is watchOS, tvOS, and for all I know there could even be a visionOS.


In any event I trust this answers your question.

Jul 23, 2023 11:39 AM in response to Ikearat

To tbirdvet and John Galt;

Thank you. I apologize for my age... desktop Mac's in my community are assumed to not have phone operating systems and we have traditionally referred to them using the anicent term "OS-X".

Again, forgive me for my failure to be current in my terminology.

The reason I included the Apple description of the update has to do with exactly the differentiation both of you bring to the discussion... exactly what operating system is this update for? The description speaks to iOS but is intended for a desktop operating system, Conflict in terminology? I think both myself and Apple are a little confused.

Jul 23, 2023 3:39 PM in response to Ikearat

Thank you John.

Actually, you didn't answer the intended question. I agree that I choose the wrong term for making the distenction between mobile device (ie: iOS) and Apple's desktop operating system. I admitted to my use of an ancient term. I am sorry I did that. I now understand that I should be careful when I ask a question, taking care to use the current name(s) for the current product types.

However, adding iPadOS and iPhoneOS and watchOS, tvOS and a guess at an additional operating system name does not clarify Apple's description of the purpose of the update which I originally questioned.

Help me get past the discussion about operating system names (before someone offers a complete history on Apple operating systems) and try to see what I am asking about.

To reiterate, why is Apple referencing iOS when they mean Mac OS? They draw attention to an issue with iOS when MacOS is the operating system being updated.

Jul 23, 2023 3:49 PM in response to John Galt

Then I venture you did not read the opening message. I repete a portion of it here for you;

"Impact: An app may be able to execute

arbitrary code with kernel privileges. Apple is aware of a report that

this issue may have been actively exploited against versions of iOS

released before iOS 15.7."

This clearly references iOS and not MacOS. What part of this is not clear?

Mac Jim ID clarified the issue and I am happy with his response. He did not school me about operating systesm, he provided clarification using Apple resources. Thank you Mac Jim ID.

Ok, having a clear answer lets me go about my life without continuing to follow this thread. You are welcome to reply and carry this discussion on for yourselves but I will not be reading of participating further.


Again, Thank You Mac Jim ID

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Is this update about iOS or OS-X?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.