25 January 2023

Apple ships zero-day patch for older iPhones, iPads


Apple ships zero-day patch for older iPhones, iPads

Apple has issued security updates for macOS, iOS, iPadOS, and WatchOS, to address a zero-day vulnerability affecting older devices running iOS v12.

Tracked as CVE-2022-42856, the zero-day is type confusion issue in the WebKit web browser engine that allows a remote attacker to achieve remote code execution by tricking the victim into visiting a malicious website.

Apple did not share any additional information regarding attacks exploiting the above mentioned flaw, but said it is “aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.”

The security issue affects iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation) devices.

Besides CVE-2022-42856, the iPhone maker fixed multiple high-risk vulnerabilities impacting its Safari browser, watchOS, iOS 16 and iPadOS 16, macOS Ventura, macOS Monterey, and macOS Big Sur.

Back to the list

Latest Posts

Cyber Security Week in Review: May 3, 2024

Cyber Security Week in Review: May 3, 2024

In brief: the Dropbox breach, Chinese hackers caught manipulating China’s Great Firewall, REvil hacker sentenced, and moreю
3 May 2024
REvil hacker sentenced to 13 years for $700M ransomware spree

REvil hacker sentenced to 13 years for $700M ransomware spree

In addition to his prison sentence, Vasinskyi was ordered to pay over $16 million in restitution.
2 May 2024
Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

The attackers accessed authentication tokens, MFA keys, hashed passwords, and customer info.
2 May 2024