There are currently two critical vulnerabilities in Apple’s smartphones, tablets and computers that attackers can exploit to gain control of the device.
Apple released an update on Thursday, August 18, 2022 that aims to close the two vulnerabilities. The manufacturer therefore recommends updating it as soon as possible.
Browser component and OS kernel with vulnerabilities
Sometimes the affected WebKit Software, which is used to display the content in the Safari web browser. The special problem here: The browsers on the iPhone and iPad run exclusively via this application.
According to the website The Hacker News Attackers are able to exploit the vulnerability in a targeted manner and execute arbitrary code on your system via manipulated web content.
According to Apple, the second security gap is in the kernel, i.e. the deepest core of the operating system. According to Apple, this vulnerability allows any code to be executed with kernel privileges. This level of rights represents the highest and is therefore all the more dangerous in connection with malware.
The Cupertino-based manufacturer also states that it has information that these vulnerabilities have already been actively exploited. Rachel Tobac, security expert and CEO of SocialProof Security, also warns of the risks and recommends a timely update:
link to Twitter content
Current iPhones, iPads and Macs are affected
Apple’s announcement shows that a number of devices are affected by the security vulnerabilities:
- iPhones: iPhone 6s and later models
- iPads: all iPad Pro models, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4th generation and later
- Mac: Mac computer with the operating system version
MacOS Montery
Also affected are iPod Touch models of the 7th generation. The latest versions of each operating system are as follows:
- iOS and iPadOS: 15.6.1
- MacOS: 12.5.1
The software update can be found in iOS and iPadOS under Settings General
and then up software update
make. Under MacOS you click in the settings
on Software-Update
to apply the latest update.