Critical vulnerability identified in Apple iOS and macOS

Australian Cyber Security Centre

Background / What has happened?

The ACSC is tracking a Remote Code Execution vulnerability in Apple WebKit. Apple WebKit is a component used extensively in iOS and macOS devices to display web pages. Apple iOS and macOS products are used widely in Australia, organisations and users should take immediate action and update their devices to prevent compromise.

CVE-2022-22620 allows a malicious actor to execute arbitrary code on an affected device if maliciously crafted web content is processed. Further information on this vulnerability is available in Apple's security advisories:

Safari 15.3

macOS Monterey 12.2.1

iOS 15.3.1 and iPadOS 15.3.1

The ACSC is aware of reported active exploitation of this vulnerability.

Mitigation / How do I stay secure?

Australians should review their devices for use of vulnerable versions of iOS and macOS and apply the available security updates as a high priority.

Assistance / Where can I go for help?

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.