Incident Response

Apple Ships Urgent iOS Patch for WebKit Zero-Day

Apple rolls out urgent iOS and iPadOS software updates and warned that zero-day exploitation has already been detected.

Apple on Monday rolled out an urgent software update to its iOS and iPadOS mobile operating systems and warned that zero-day exploitation has already been detected.

For the second time since adopting the “rapid security responses” process to address zero-day attacks, Apple pushed iOS 16.5.1 (a) and iPadOS 16.5.1 (a) to devices globally after an anonymous researcher disclosed the underlying vulnerability.

A barebones advisory from Cupertino said the security defect exists in WebKit, the browser engine used by Safari, Mail, AppStore and many other apps on iOS- and macOS-powered devices.

“Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited,” the company said. “The issue was addressed with improved checks.”

The vulnerability has been tagged as CVE-2023-37450.

So far in 2023, there have been 41 publicly documented cases of zero-day attacks with more than one-fifth (22 percent) affecting software code on Apple devices.

July 11 Update: Apple released Rapid Response Updates for both iOS and macOS, but was forced to pull them after users reported that the patches were breaking some websites.

Related: Problems Installing Apple’s First iOS Rapid Security Response Patch 

Advertisement. Scroll to continue reading.

Related: Apple Ships Urgent iOS Patch for Exploited Zero-Days

Related: Apple Fixes Exploited Zero-Day With iOS 16.1 Patch

Related: Apple Says WebKit Zero-Day Hitting iOS, macOS Devices

Related Content

Tracking & Law Enforcement

Apple and Google have rolled out a new mobile feature that warns users of unwanted trackers moving with them.

Vulnerabilities

Google has patched CVE-2024-4761, the second exploited vulnerability addressed by the company within one week.

Malware & Threats

Apple documents another zero-day flaw being exploited on older iPhones and documents security problems in macOS, iOS and iPadOS.

Vulnerabilities

A Chrome 124 update patches the second Chrome zero-day that has been found to be exploited in malicious attacks in 2024.

Nation-State

MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities.

Malware & Threats

More than 1,400 CrushFTP servers remain vulnerable to an actively exploited zero-day for which PoC has been published.

Malware & Threats

Palo Alto Networks has started releasing hotfixes for the firewall zero-day CVE-2024-3400, which some have linked to North Korea’s Lazarus. 

Malware & Threats

Microsoft patches CVE-2024-29988 and CVE-2024-26234, two zero-day vulnerabilities exploited by threat actors to deliver malware.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version