ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Apple Patches iPhone Zero-Day

criticalExploit / PoC exploited in the wildimportance 60
Full article142 words · extracted from schneier.com · click to collapse

The most recent iPhone update—to version 16.2—patches a zero-day vulnerability that “may have been actively exploited against versions of iOS released before iOS 15.1.”

News:

Apple said security researchers at Google’s Threat Analysis Group, which investigates nation state-backed spyware, hacking and cyberattacks, discovered and reported the WebKit bug.

WebKit bugs are often exploited when a person visits a malicious domain in their browser (or via the in-app browser). It’s not uncommon for bad actors to find vulnerabilities that target WebKit as a way to break into the device’s operating system and the user’s private data. WebKit bugs can be “chained” to other vulnerabilities to break through multiple layers of a device’s defenses.

Tags: Apple, iOS, iPhone, patching, zero-day

Posted on December 16, 2022 at 7:04 AM15 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2022/12/apple-patches-iphone-zero-day.html