Apple has released security updates to fix, among other things, two zero-day vulnerabilities . One of them has already been publicly disclosed and the other is already being used by malicious users trying to hack iPhones and Macs .
See also: German government: APT27 group breaches business networks

The first zero-day vulnerability that Apple has patched, known as CVE-2022-22587, is a memory corruption bug in IOMobileFrameBuffer. The bug affects iOS, iPadOS, and macOS Monterey. Successful exploitation of this bug leads to code execution with kernel privileges on compromised devices.
"Apple has learned that this issue could be exploited by malicious users," Apple said when describing the zero-day bug.
The Apple devices affected by the memory corruption zero-day bug are:
- iPhone 6s and later models
- iPad Pro (all models)
- iPad Air 2 and later models
- iPad 5th generation and later models
- iPad mini 4 and later models
- iPod touch (7th generation)
- macOS Monterey
The bug was discovered by an anonymous researcher and Meysam Firouzi (@R00tkitSMM) of MBition – Mercedes-Benz Innovation Lab and Siddharth Aeri (@b1n4r1b01).
See also: LockBit ransomware: Linux version targets VMware ESXi servers

The second zero-day is a WebKit in Safari, affecting iOS and iPadOS, that allows websites to track users' browsing activity and identities in real time.
The bug was first disclosed to Apple by Martin Bajanik of FingerprintJS on November 28, 2021, and was publicly disclosed about two weeks ago, on January 14, 2022. The vulnerability is known as CVE-2022-22594 and is fixed in the iOS 15.3 and iPadOS 15.3 security update.
See also: New DeadBolt ransomware targets QNAP NAS devices
These are the first zero-day vulnerabilities fixed by Apple in 2022.
However, over the past year, Apple has patched a large number of zero-day vulnerabilities that were used in attacks against iOS and macOS devices.
Source: Bleeping Computer
