Endpoint Security

Apple Patches WebKit Flaws Exploited on Older iPhones

Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1.

iPhone exploit

Apple on Thursday pushed out security updates for its flagship macOS and iOS platforms to cover a pair of serious flaws that have already been exploited against older mobile devices.

The vulnerabilities, flagged in the WebKit browsing engine, can be exploited to hijack sensitive content or launch arbitrary code execution attacks, according to a series of advisories from Cupertino.

The company rolled out iOS 17.1.2 and iPadOS 17.1.2 with fixes for the WebKit flaws and warned that exploits can be launched via malicious web content.

“Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1,” the company said.

As is customary, Apple’s advisories did not provide any additional information on in-the-wild exploitation.

The company credited the discoveries to Clément Lecigne of Google’s Threat Analysis Group (TAG). Google’s researchers have actively discovered commercial spyware vendors and mercenary hacking companies exploiting iPhone zero-day vulnerabilities.

The WebKit memory safety bugs — CVE-2023-42916 and CVE-2023-42917 — were also patched in the new macOS Sonoma 14.1.2 and Safari 17.1.2 updates.

Related: Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices

Advertisement. Scroll to continue reading.

Related: Okta Broadens Scope of Hack: All Customer Support Users Affected

Related: Google Patches Seventh Chrome Zero-Day of 2023

Related Content

Vulnerabilities

Apple has released iOS 17.4.1 and macOS Sonoma 14.4.1 with patches for an arbitrary code execution vulnerability.

Data Protection

Researchers detail GoFetch, a new side-channel attack impacting Apple CPUs that could allow an attacker to obtain secret keys.

Threat Intelligence

Red Canary’s 2024 Threat Detection Report is based on analysis of almost 60,000 threats across 216 petabytes of telemetry from over 1,000 customers’ endpoints.

Mobile & Wireless

Apple is opening small cracks in the iPhone’s digital fortress as part of a regulatory clampdown in Europe— at the risk of creating new...

Vulnerabilities

High-severity vulnerability in Apple Shortcuts could lead to sensitive information leak without user’s knowledge.

Data Protection

Apple unveils PQ3, a new post-quantum cryptographic protocol for iMessage designed to protect communications against quantum computing attacks.

Vulnerabilities

Apple’s latest Magic Keyboard firmware addresses a recently disclosed Bluetooth keyboard injection vulnerability.

Mobile & Wireless

Chinese state-backed experts have found a way to identify people who use Apple's encrypted AirDrop messaging service, according to the Beijing municipal government.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version