Security News > 2022 > February > Apple Patches Actively Exploited WebKit Zero Day

Apple Patches Actively Exploited WebKit Zero Day
2022-02-11 13:45

Apple has patched yet another zero-day vulnerability, this time in its WebKit browser engine, that threat actors already are actively exploiting to compromise iPhones, iPads and MacOS devices.

"Apple is aware of a report that this issue may have been actively exploited," the company wrote in its update notes.

Apple released separate security updates for its products to address the issue - macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1.

The flaw affects numerous Apple devices, including iPhone 6s and later; all iPad Pro models, iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch 7th generation.

The update is the second time this year that Apple has had to issue a patch for a zero day.

Last year Apple also patched several zero-day vulnerabilities, including a zero-click zero-day exploited by the NSO Group's Pegasus spyware and a memory-corruption flaw in its iOS and macOS platforms that could allow for system takeover.


News URL

https://threatpost.com/apple-patches-actively-exploited-webkit-zero-day/178370/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 68 212 1433 2208 257 4110
Webkit 2 0 1 6 0 7