• News/
  • threatpost-180448

iPhone Users Urged to Update to Patch 2 Zero-Days

Threatpost
·
Elizabeth Montalbano
·
Published Aug 19, 2022
·
Updated

Apple is urging macOS, iPhone and iPad users immediately to install respective updates this week that includes fixes for two zero-days under active attack. The patches are for vulnerabilities that allow attackers to execute arbitrary code and ultimately take over devices. Patches are available for effected devices running iOS 15.6.1 and macOS Monterey 12.5.1. Patches address two flaws, which basically impact any Apple device that can run either iOS 15 or the Monterey version of its desktop OS, according to security updates released by Apple Wednesday. One of the flaws is a kernel bug (CVE-2022-32894), which is present both in iOS and macOS. According to Apple it is an “out-of-bounds write issue [that] was addressed with improved bounds checking.” The vulnerability allows an application to execute arbitrary code with kernel privileges, according to Apple, which, in usual vague fashion, said there is a report that it “may have been actively exploited.” The second flaw is identified as a WebKit bug (tracked as CVE-2022-32893), which is an out-of-bounds write issue that Apple addressed with improved bounds checking. The flaw allows for processing maliciously crafted web content that can lead to code execution, and also has been reported to be under active exploit, according to Apple. WebKit is the browser engine that powers Safari and all other third-party browsers that work on iOS. The discovery of both flaws, about which little more beyond Apple’s disclosure are known, was cred...

Read full article

Affected Software

2 affected components
Apple iOS<15.6.1
Apple macOS Monterey<12.5.1

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Apple urging users to update their iOS and macOS devices due to patches for two active zero-day vulnerabilities.

2

What security implications are discussed in the article?

The vulnerabilities allow attackers to execute arbitrary code and potentially take control of affected devices.

3

What specific products or software are affected by the vulnerabilities?

The affected products are Apple iOS and Apple macOS Monterey.

4

How urgent is the update recommended by Apple in the article?

Apple recommends that users update immediately to protect their devices from active threats.

5

What types of devices are impacted by the vulnerabilities mentioned in the article?

The vulnerabilities affect iPhones, iPads, and macOS devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203