Apple releases urgent security fix for iPhone and Mac devices
Yet another zero-day iOS and macOS vulnerability exploited in the wild
Apple has issued iOS, iPadOS and macOS security patches for a major vulnerability that was found to be affecting a large number of its device.
The vulnerability, tracked as CVE-2022-22620, was being abused in the wild, allowing threat actors to execute any code (including malware) on a compromised device, or even crash the OS.
"Apple is aware of a report that this issue may have been actively exploited," the company said in the announcement following the release of the patch, which is part of iOS and iPadOS versions 15.3.1., while macOS Monterey is now at 12.2.1.
Numerous models affected
All iPhones, from iPhone 6S onwards, are affected by the vulnerability, as are all models of the iPad Pro, all iPad Air models starting from Air 2, iPad 5 and onwards, iPad mini 4 and newer, as well as the iPod touch 7. Furthermore, all Macs running macOS Monterey were vulnerable.
So far, it appeares that the vulnerability was likely only used in targeted attacks, meaning the average user is probably under no immediate threat. Still, everyone is advised to update their devices to the newest version, as soon as possible.
When it comes to patching up dangerous system vulnerabilities, Apple has started the year on a high note. Last month, two of the zero-days that were found to have been exploited in the wild were patched - CVE-2022-22587 and CVE-2022-22594. These affected iPhones, mac OS Monterey-powered Macs, and a couple of iPads.
Late last year, the company was criticized for being slow to respond to news of newly discovered zero-days. It has even gotten to the point where the company had to issue a formal apology to the cybersecurity community:
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
"We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," an Apple employee wrote in an email to a cybersecurity researcher Denis Tokarev last September.
- Here's our rundown of the best endpoint security solutions right now
Via: BleepingComputer
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.