3

New macOS 12.5.1 and iOS 15.6.1 updates patch “actively exploited” vulnerabiliti...

 2 years ago
source link: https://arstechnica.com/gadgets/2022/08/apple-releases-macos-12-5-1-and-ios-15-6-1-for-actively-exploited-vulnerabilities/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

patch now —

New macOS 12.5.1 and iOS 15.6.1 updates patch “actively exploited” vulnerabilities

Kernel and WebKit bugs can allow arbitrary code execution on Apple's devices.

Andrew Cunningham - 8/17/2022, 7:16 PM

Psychedelic illustration of two hills.

Apple has released a trio of operating system updates to patch security vulnerabilities that it says "may have been actively exploited." The macOS 12.5.1, iOS 15.6.1, and iPadOS 15.6.1 updates are available for download now and should be installed as soon as possible.

The three updates all fix the same pair of bugs. One, labeled CVE-2022-32894, is a kernel vulnerability that can allow apps "to execute arbitrary code with kernel privileges. The other, CVE-2022-32893, is a WebKit bug that allows for arbitrary code execution via "maliciously crafted web content." Both discoveries are attributed to an anonymous security researcher. WebKit is used in the Safari browser as well as in apps like Mail that use Apple's WebViews to render and display content.

Apple didn't release equivalent security patches for macOS Catalina or Big Sur, two older versions of macOS that are still receiving regular security updates. We've contacted Apple to see whether it plans to release these patches for these older OSes, or if they aren't affected by the bugs and don't need to be patched.

Apple's software release notes for the updates don't reference any other fixes or features. Apple is actively developing iOS 16, iPadOS 16, and macOS Ventura, and those updates are due out later this fall.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK