Security News > 2022 > March > Apple patches 87 security holes – from iPhones and Macs to Windows
The latest raft of non-emergency Apple security updates are out, patching a total of 87 different CVE-rated software bugs across all Apple products and plaforms.
With 87 noteworthy bugs in the mix, there are plenty of security issues to choose from, including several that are listed with a warning that the bug might "Lead to arbitrary code execution", or even that it might be exploitable "To execute arbitrary code with kernel privileges".
Three remote code execution bugs are listed in WebKit, the HTML rendering code that underlies all of Apple's own web browsing code, including Safari, and that underlies all web browsing on App Store programs.
There's a similar and equally alarming set of bugs in the document, audio and video viewing components on iPhones and iPads.
If a moderately dangerous remote code execution bug is combined with an EoP, short for elevation-of-privilege exploit, then the attacker's remotely triggered malware code may be able not only to get in, but also to move around, effectively evading the "Each-app-is-cloistered-in-its-own-little-world" sandbox protection usually imposed by the operating system.
Note that there's also an update for iTunes on Windows that closes a number of remote code execution bugs, including not only the abovementioned WebKit holes, but also various related image-handling bugs that could allow a booby-trapped file to take over your computer even if all you did was look at it.
News URL
Related news
- Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More (source)
- SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon (source)
- Windows 11 installation media bug causes security update failures (source)
- Windows 11 Media Update Bug Stops Security Updates (source)
- Windows 10 users urged to upgrade to avoid "security fiasco" (source)
- Security pros baited with fake Windows LDAP exploit traps (source)
- 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now (source)
- Microsoft: January Windows security updates break audio playback (source)
- Apple plugs security hole in its iThings that's already been exploited in iOS (source)
- Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) (source)