Apple's iOS 14.4 update is now live - and as well as plugging a security hole, it will help with Covid-19 poster scanning.
Late yesterday Crown agency CERT NZ (the Computer Emergency Response Team) issued an advisory about a security vulnerability with iOS that Apple says is being actively exploited by hackers.
The issue relates to iOS (the software that runs iPhones), iPadOs and tvOS (the software that runs Apple TVs).
"Immediately update your Apple iOS, iPadOS and tvOS devices to version 14.4 where the update is available. For most users, a pop-up should alert you that an update is available – select 'Update Now'," CERT NZ's advisory said.
"If you do not receive a pop-up message, follow these steps: Go to Settings > System > Software Update. In there, select "Update Software".
At the time, iOS 14 was not available. It should now appear as an option for most users (Apple typically makes iOS updates available on a rolling basis). The update took the Herald about 10 minutes to update and install.
Details on the security vulnerability scant at this stage, but an Apple notification page on the issue says, "A malicious application may be able to elevate privileges," if it exploits the security vulnerability, indicating it potential for a hacker to take control of a device.
"Apple is aware of a report that this issue may have been actively exploited," the iPhone maker says on its security notification page.
The company says it does not provide detail on security issues until after they have been patched.
iOS 14.4 also adds support for snapping smaller QR codes - a useful addition as we're all being encouraged to up our Covid poster scanning.
CERT NZ recommends that users enable an automatic software update function for software on any device.
The announcement took some of the gloss off off Data Privacy Day, which saw Facebook boss Mark Zuckerberg riled by an Apple move to make advertisers disclose when they want to track your activity.
Zuckerberg called the move anticompetive. Apple said it was responding to users' demands for more privacy and transparency, and released a "Day in the Life of Your Data" presentation to push its case.