Apple Patches Two Actively Exploited Zero-Days Affecting iPhone and Mac

Apple has released emergency updates fixing two zero-day vulnerabilities that are being actively exploited in the wild. If you’re running iOS 15 or macOS Monterey, you need to update now.

The first flaw, CVE-2022-32894, is a kernel vulnerability affecting both iOS and macOS. It’s an out-of-bounds write issue that lets an application execute arbitrary code with kernel privileges — essentially giving an attacker the keys to the entire device. Apple says it’s aware of reports that this one may have already been actively exploited.

The second, CVE-2022-32893, lives in WebKit — the browser engine that powers Safari and every third-party browser on iOS. It’s also an out-of-bounds write flaw. Processing maliciously crafted web content through a browser can lead to code execution. Also reportedly under active attack.

Both were discovered by an anonymous researcher. Patches are available in iOS 15.6.1 and macOS Monterey 12.5.1.

Security expert Rachel Tobac put it bluntly: most people should update by end of day. Journalists, activists and anyone at elevated risk from nation-state threats should drop everything and patch immediately. The combination of these flaws could theoretically create a Pegasus-like scenario, where a single interaction with a malicious web page compromises the entire device.

These fixes come alongside Google patching Chrome’s fifth zero-day of the year — it’s been a busy month for emergency patches across the industry.

References