Apple just patched a load of iOS and iPadOS security flaws, so update now

holding an iphone
(Image credit: Shutterstock)

Apple has released iOS 16.4 and is urging iPhone users, particularly those with older devices, to update immediately to benefit from some important security fixes

Despite the seemingly unassuming update number (16.x, rather than 16.x.x), this update has patched 32 known security flaws that have been plaguing iOS 16 users for some time, making it a vital update even if you’re not chasing the latest features.

Among the patched vulnerabilites is a fix for a WebKit type confusion issue that hackers could use trigger OS crashes and gain code execution on compromised iOS and iPadOS devices.

iOS 16.4 security update

If successful, anyone utilizing the flaw could then be able to execute arbitrary code, most likely by tricking the victims into opening malicious web pages.

"Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited," Apple describes the zero-day. "Apple is aware of a report that this issue may have been actively exploited."

Older iPhone devices are particularly susceptible, with the list of impacted devices including iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) devices.

Elsewhere, iOS 16.4 also amends a worrying Calendar fault that could have seen malicious invitations leaking user information, as well as further fixes including the Photos app’s Hidden Photos Album which has allowed access without authentication via Visual Lookup, a handful of Safari and WebKit flaws including one that saw some user information be trackable, and a number of kernel-related issues.

More broadly, macOS 13.3 fixes issues relating to trackpad gestures and accessibility features, while iOS 16.4 has also added support for home screen web apps by third-party browsers, a new order tracking widget for Apple Pay purchases as part of the Wallet app, voice isolation for cellular calls (as well as video and VoIP calls as before), and other UI tweaks.

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Apple iPhone 16 Review
iOS 18.3 is here with a major change to how you enable Apple Intelligence
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand