Apple releases urgent security fix for iPhone and Mac devices

iPhone running iOS 15
iPhone OS 15 (Image credit: Shutterstock)

Apple has issued iOS, iPadOS and macOS security patches for a major vulnerability that was found to be affecting a large number of its device. 

The vulnerability, tracked as CVE-2022-22620, was being abused in the wild, allowing threat actors to execute any code (including malware) on a compromised device, or even crash the OS. 

"Apple is aware of a report that this issue may have been actively exploited," the company said in the announcement following the release of the patch, which is part of iOS and iPadOS versions 15.3.1., while macOS Monterey is now at 12.2.1.

Numerous models affected

All iPhones, from iPhone 6S onwards, are affected by the vulnerability, as are all models of the iPad Pro, all iPad Air models starting from Air 2, iPad 5 and onwards, iPad mini 4 and newer, as well as the iPod touch 7. Furthermore, all Macs running macOS Monterey were vulnerable. 

So far, it appeares that the vulnerability was likely only used in targeted attacks, meaning the average user is probably under no immediate threat. Still, everyone is advised to update their devices to the newest version, as soon as possible. 

When it comes to patching up dangerous system vulnerabilities, Apple has started the year on a high note. Last month, two of the zero-days that were found to have been exploited in the wild were patched - CVE-2022-22587 and CVE-2022-22594. These affected iPhones, mac OS Monterey-powered Macs, and a couple of iPads. 

Late last year, the company was criticized for being slow to respond to news of newly discovered zero-days. It has even gotten to the point where the company had to issue a formal apology to the cybersecurity community: 

"We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," an Apple employee wrote in an email to a cybersecurity researcher Denis Tokarev last September.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras