• News/
  • https://threatpost.com/iphone-users-urged-to-update-to-patch-2-zero-days-under-attack/180448/

iPhone Users Urged to Update to Patch 2 Zero-Days Under Attack

Threatpost
·
Elizabeth Montalbano
·
Published Aug 19, 2022
·
Updated

Apple is urging macOS, iPhone and iPad users immediately to install respective updates this week that includes fixes for two zero-days under active attack. The patches are for vulnerabilities that allow attackers to execute arbitrary code and ultimately take over devices. Patches are available for effected devices running iOS 15.6.1 and macOS Monterey 12.5.1. Patches address two flaws, which basically impact any Apple device that can run either iOS 15 or the Monterey version of its desktop OS, according to security updates released by Apple Wednesday. One of the flaws is a kernel bug (CVE-2022-32894), which is present both in iOS and macOS. According to Apple it is an “out-of-bounds write issue [that] was addressed with improved bounds checking.” The vulnerability allows an application to execute arbitrary code with kernel privileges, according to Apple, which, in usual vague fashion, said there is a report that it “may have been actively exploited.” The second flaw is identified as a WebKit bug (tracked as CVE-2022-32893), which is an out-of-bounds write issue that Apple addressed with improved bounds checking. The flaw allows for processing maliciously crafted web content that can lead to code execution, and also has been reported to be under active exploit, according to Apple. WebKit is the browser engine that powers Safari and all other third-party browsers that work on iOS. The discovery of both flaws, about which little more beyond Apple’s disclosure are known, was cred...

Read full article

Affected Software

2 affected components
Apple iOS=15.6.1
Apple macOS Monterey=12.5.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses urgent security updates from Apple for iOS and macOS users to fix two zero-day vulnerabilities.

2

What security implications are discussed?

The vulnerabilities allow attackers to execute arbitrary code, potentially leading to full device takeover.

3

What products or software are affected?

The affected products include Apple iPhones, iPads, and macOS Monterey.

4

What should users do in response to this article?

Users are urged to immediately install the latest updates to protect their devices from exploitation.

5

When were the patches released?

The patches were released during the week of August 19, 2022.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203