Security News > 2022 > January > Apple fixes Safari data leak (and patches a zero-day!) – update now
Just under two weeks ago, we wrote about an Apple Safari bug that could allow rogue website operators to track you even if they gave every impression of not doing so, and even if you had strict privacy protection turned on.
That vulnerability, now known as CVE-2022-22594, showed up in Safari because of a bug in WebKit, the "Browser rendering engine", as these things are generally known, on which the Safari app is based.
Although Safari is the only mainstream WebKit-based browser on Apple's macOS, that's not the case on Apple's mobile devices.
Of course, the big-news Safari "Supercookie" bug isn't the only security hole patched in this batch of updates: numerous other yet-more-serious bugs were patched as well.
These security updates can be considered critical, given the number of remote code execution bugs that could, in theory at least, be used without your consent to install covert surveillance software, implant malware, steal data, secretly jailbreak your device, and more.
On iOS 15, iPadOS 15, Monterey 12 and BigSur 11, one of the RCE bugs that potentially gives kernel-level control - typically the worst sort of RCE bug you can get - is listed with Apple's typically understated warning that the company "Is aware of a report that this issue may have been actively exploited."
News URL
Related news
- Clop ransomware threatens 66 Cleo attack victims with data leak (source)
- Telefónica confirms internal ticketing system breach after data leak (source)
- Apple fixes this year’s first actively exploited zero-day bug (source)
- Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More (source)
- Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) (source)
- SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-18 | CVE-2022-22594 | Origin Validation Error vulnerability in Apple products A cross-origin issue in the IndexDB API was addressed with improved input validation. | 6.5 |