Apple releases another urgent iOS security patch, so install now

password manager security
(Image credit: Passwork)

Apple has released an urgent security patch that addresses multiple flaws in different versions of iOS, iPad OS, and macOS. Some of these flaws, the company confirmed, are being actively abused in the wild. 

“Apple is aware of a report that this issue may have been actively exploited.” the company said in a security advisory without going into detail about who is abusing what, exactly. 

The patch fixes a total of five security updates, covering 16 CVEs affecting Safari 16 on macOS Big Sur, macOS Monterey, iOS 16 on iPhone 8 and newer, as well as macOS Monterey 12.6, macOS Big Sur 11.7, and iOS 15.7 and iPadOS 15.7 on most of its devices. The company is also working to address the issues on tvOS. 

Arbitrary code execution

Of all the CVEs addressed in this security update, two are being actively exploited, as they allow for arbitrary code execution, it was said. 

One is CVE-2022-32917, which allows malicious apps to execute arbitrary code with kernel privileges. This one was fixed, the company said, with improved bounds checks. The second one is CVE-2022-32894, abused against computers running macOS Big Sur 11.7. This one also allows for arbitrary code execution, and is caused by an out-of-bounds write flaw. Apple fixed this one the same way, with improved bounds checking. 

Anonymous tipsters drew Apple’s attention to these flaws, the company added.

The fixes were released mere days after Apple introduced iOS 16, a release that brings improvements to many apps, from a redesigned Home app for your smart appliances to better privacy features, and a big focus on the lock screen, with new fonts, colors, and themes to choose from. 

There's also satellite calling coming to the newly-announced iPhone 14 models, a feature coming in November 2022.

Via: The Register

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand