Apple has released security updates to fix a zero-day vulnerability that could be used to attack iPhones and Macs. In security advisories published on Monday, the company revealed that it has received reports that the zero-day vulnerability. is likely being actively exploited

The bug is tracked as CVE-2022-32917 and could allow applications maliciously crafted
See also: Apple Watch Ultra repairs are prohibitively expensive without AppleCare
Apple learned of the vulnerability from an anonymous researcher, and it has been patched in iOS 15.7 and iPadOS 15.7, macOS Monterey 12.6, and macOS Big Sur 11.7 with improved bounds checks.
Which Apple devices are affected by the new zero-day vulnerability:
- iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, iPod touch (7th generation)
- and Mac with macOS Big Sur 11.7 and macOS Monterey 12.6
Apple also issued patches for another zero-day vulnerability (CVE-2022-32894) in Macs running macOS Big Sur 11.7, after releasing additional security updates on August 31 to address the same bug in versions of iOS running on older iPhones and iPads.
See also: Apple introduced the iPhone 14, new Apple Watch models & AirPods Pro 2

Apply updates to keep your iPhone and Mac secure
As we mentioned above, this vulnerability is said to be actively being exploited, but Apple has not provided any information about the attacks. It apparently wants to give users to apply the updates to devices before other attackers develop their own exploits and start deploying them in attacks targeting vulnerable iPhones and Macs.
The company recommends immediately updating vulnerable devices to block any attack attempts.
See also: What should we do to deal with ransomware?
This is the eighth zero-day vulnerability that Apple has patched since the beginning of 2022:
- In January, Apple patched two more zero-day bugs that allowed code execution with kernel privileges (CVE-2022-22587) and web browsing activity monitoring (CVE-2022-22594).
- In February, the company released security updates to fix another WebKit flaw that was exploited in attacks against iPhones, iPads, and Macs.
- In March, two zero-day bugs in the Intel Graphics Driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675).
- In August, it fixed two zero-day vulnerabilities in iOS Kernel (CVE-2022-32894) and WebKit (CVE-2022-32893).
Source: www.bleepingcomputer.com
