Apple has released emergency security updates to fix two zero-day vulnerabilities that allow cybercriminals to compromise iPhones, iPads, and Macs .
The company said it has received reports that suggest the vulnerabilities are already being exploited by malicious users.
See also: Apple and Meta shared data with hackers pretending to be researchers

The first zero-day vulnerability in Apple products is an "out-of-bounds write issue" (CVE-2022-22674) found in the Intel Graphics Driver. The second vulnerability is an "out-of-bounds read issue" (CVE-2022-22675) in the AppleAVD media decoder that allows applications to execute code with kernel privileges.
Apple was notified of the zero-day bugs by anonymous researchers and fixed them with theiOS 15.4.1, iPadOS 15.4.1, and macOS Monterey 12.3.1.
According to the company, the devices affected by the two zero-day vulnerabilities are:
- iPhone 6s and later models
- iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation).
- Macs running macOS Monterey
See also: Apple: Reader apps will sign up new subscribers without paying fees
While Apple said that the zero-day vulnerabilities are being used to compromise iPhones, iPads, and Macs, it did not provide further details about the attacks. The company, apparently, chose not to reveal all the information it has until the updates are installed on as many iPhones, iPads, and Macs as possible. This will prevent other threat actors from learning the details. It is believed that the zero-day vulnerabilities have only been used in targeted attacks, but Apple is urging its users to update their devices immediately to block potential attack attempts.

Apple: New zero-day vulnerabilities are constantly appearing
In January, Apple patched two more active zero-day bugs. One could allow attackers to execute code with kernel privileges (CVE-2022-22587). The second allowed users' online activity to be monitored and their identities tracked in real time (CVE-2022-22594).
Last month, Apple released updates for another zero-day bug. The vulnerability affected iPhones, iPads, and Macs, causing problems with the operating system and allowing remote code execution on compromised devices.
See also: Zero-day in Java Spring allows remote code execution
The company also addressed multiple zero-day vulnerabilities in iOS, iPadOS, and macOS throughout 2021.
Apple products (iPhone, iPad, Mac) are used by a large number of users and the company tries to promptly fix such security issues to keep its customers safe.

A few words about zero-day vulnerabilities
"Zero-day" is a broad term that describes newly discovered security issues that hackers to attack systems. Essentially, it is a vulnerability that has been discovered by attackers/researchers before the company has identified it. Since the vendors of the vulnerable products are not aware of the vulnerability, they do not have a patch, increasing the chances of an attack being successful. For this reason, companies rush to fix vulnerabilities as soon as they become known.
Source: Bleeping Computer
