Update your iPhone now – Apple just fixed a big iOS 17 security flaw

An iPhone showing an iOS 17 security update
(Image credit: Future)

If you have an iPhone, iPad or Mac, you need to update it today, because Apple has just fixed two zero-day exploits that could allow hackers to steal your private data. In fact, Apple says the vulnerabilities have been actively exploited in the wild, meaning the danger isn’t just hypothetical.

Security notes from Apple (via Bleeping Computer) explain that both issues relate to the company’s WebKit browser engine that's used in Safari on all platforms, and in every browser that runs on iOS and iPadOS (including those made by third-party developers). They affect iOS, iPadOS and macOS, which means the reach of these vulnerabilities is potentially huge.

For one of the issues, “processing web content may disclose sensitive information” due to an out-of-bounds read bug, Apple says. In the other, there’s a risk that processing web content might allow a hacker to execute arbitrary code thanks to a memory corruption vulnerability.

The fixes are contained in the iOS 17.1.2, iPadOS 17.1.2 and macOS 14.1.2 updates, as well as Safari 17.1.2 for macOS Monterey and macOS Ventura. These updates should be downloaded as soon as possible if you have an iPhone, an iPad or a Mac.

On your iPhone, just go to Settings > General > Software Update, and you should see the iOS 17.1.2 update appear. Be aware that it requires at least 7GB of storage to be available during installation, so you may need to delete some files if you're close to your limit.

Actively exploited

Entering passcode on an iPhone

(Image credit: Shutterstock)

The key danger with these flaws is that they are being actively abused in the wild. As noted in a statement from the company, “Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.”

Apple says the following products are affected, so check to see if your own devices are listed:

  • iPhone XS and later
  • iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
  • macOS Monterey, macOS Ventura and macOS Sonoma

A zero-day exploit is a flaw that the developers of the app or operating system were not originally aware of. That makes them particularly dangerous, because until the developer has noticed and fixed them, they can be exploited for nefarious purposes.

The latest security flaws are a reminder to keep your devices up to date at all times and to download security patches as soon as they become available. Where available, make sure you turn on automatic security updates to keep yourself safe.

You might also like

TOPICS
Alex Blake
Freelance Contributor

Alex Blake has been fooling around with computers since the early 1990s, and since that time he's learned a thing or two about tech. No more than two things, though. That's all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in iPhone
Apple iPhone 16 Review
New iPhone 17 report lends weight to rumors of major display and camera upgrades, and a pricey Apple foldable
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
The home screen on an iPhone 16e smartphone
I think the iPhone 16e is too expensive – and as it turns out, so does nearly everybody else
Apple iPhone 16 on orange background with big savings text overlay
You can get a free iPhone 16 Pro Max without a trade at Verizon right now - with one minor catch
Apple CEO Tim Cook
Forget Siri, Apple needs to launch a folding iPhone and get back on track
Latest in News
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
DJI Mavic 3 Pro
More DJI Mavic 4 Pro leaks seemingly reveal launch date, price and key features of the triple camera drone – here's what to expect
Android 16 logo on a phone
Here's how Android 16 will upgrade the screen unlocking process on your Pixel
Man sitting on sofa, drinking coffee, looking at phone in surprise
Thousands of coffee lovers warned to stop using their espresso machines immediately after reports of burns and lacerations