Apple has addressed a new zero-day vulnerability used to attack iPhones by releasing security updates.

A zero-day vulnerability is a vulnerability in software or hardware that the vendor is unaware of (until it is exploited or discovered by a researcher). These types of vulnerabilities are particularly dangerous because they can be exploited by attackers before the vendor has a chance to patch them. That's why they're called "zero-day" - because there are zero days between the time the vulnerability is discovered and the time it can be exploited.
See also: Windows zero-day: JavaScript files bypass MoTW
Apple said in a security advisory released yesterday that it is aware of reports that the zero-day bug "may have been exploited."
The CVE-2022-42827 is an out-of-bounds write caused by software writing data outside the boundaries of the current memory buffer. Apple was notified of the bug by an anonymous researcher.
Exploitation of the flaw may lead to data corruption, application crashes, or code execution.
See also: A zero-day in Windows Mark of the Web gets an unofficial update
According to Apple, successful exploitation of this zero-day vulnerability could allow potential attackers to execute code with kernel privileges.
The affected devices are: iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation.
With the release of iOS 16.1 and iPadOS 16, Apple fixed this new zero-day vulnerability.

Update your iPhones and iPads to protect yourself
While Apple has confirmed that there are reports of people actively exploiting this vulnerability, it has not provided details about these attacks.
This way, Apple customers will be able to update their devices before attackers have a chance to create new ways to exploit the zero-day vulnerability to attack iPhones and iPads.
See also: 900 servers compromised using a zero-day Zimbra vulnerability
Current security updates are important to install, even though the zero-day flaw is likely only used in targeted attacks. By installing the update, you will be able to block any attack attempts.
Since the beginning of the year, Apple has fixed several zero-day bugs.
- In September, Apple released a security update to address a flaw in the iOS Kernel (CVE-2022-32917).
- In August, it fixed two more zero-days in the iOS Kernel (CVE-2022-32894) and WebKit (CVE-2022-32893).
- In March, Apple patched two zero-days in the Intel Graphics Driver (CVE-2022-22674) and AppleAVD (CVE-2022-22675).
- In February, the company released security updates to fix a zero-day bug in WebKit that was used to attack iPhones, iPads, and Macs.
- In January, Apple fixed two more zero-day bugs that allowed code execution with kernel privileges (CVE-2022-22587) and the monitoring of users' web browsing activity (CVE-2022-22594)
Source: www.bleepingcomputer.com
