← Back to BrewedIntel
vulnerabilitycriticalRemote Code ExecutionZero-Day Exploitation

Aug 19, 2022 • Elizabeth Montalbano

iPhone Users Urged to Update to Patch 2 Zero-Days

Apple has released security updates for macOS and iOS addressing two actively exploited zero-day vulnerabilities. The first flaw resides in the kernel...

Source
Threatpost
Category
vulnerability
Severity
critical

Executive Summary

Apple has released security updates for macOS and iOS addressing two actively exploited zero-day vulnerabilities. The first flaw resides in the kernel component, while the second affects WebKit, the browser rendering engine used across Apple devices. Both vulnerabilities allow threat actors to achieve remote code execution and complete device takeover. Apple has confirmed that these vulnerabilities are being actively exploited in the wild, indicating immediate risk to unpatched devices. Users of iPhones, iPads, and Macs are strongly urged to update to the latest software versions immediately to mitigate potential compromise. Organizations should prioritize patching mobile device fleets given the active exploitation status.

Summary

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Published Analysis

Apple has released security updates for macOS and iOS addressing two actively exploited zero-day vulnerabilities. The first flaw resides in the kernel component, while the second affects WebKit, the browser rendering engine used across Apple devices. Both vulnerabilities allow threat actors to achieve remote code execution and complete device takeover. Apple has confirmed that these vulnerabilities are being actively exploited in the wild, indicating immediate risk to unpatched devices. Users of iPhones, iPads, and Macs are strongly urged to update to the latest software versions immediately to mitigate potential compromise. Organizations should prioritize patching mobile device fleets given the active exploitation status. Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack. Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.