Apple has released emergency security updates to address two zero-day vulnerabilities used in attacks against iPhones, iPads, and Macs .
Attackers are likely exploiting vulnerabilities in iOS versions prior to iOS 16.7.1, according to Apple.

The two zero-day vulnerabilities (CVE-2023-42916 and CVE-2023-42917) were discovered in the WebKit browser engine and allow attackers to gain access to sensitive information via an out-of-bounds read weakness. They also allow code execution via a memory corruption bug on vulnerable devices via maliciously crafted websites.
See also: Google fixes new zero-day vulnerability in Chrome
Apple says it has addressed the two zero-day vulnerabilities in versions iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2.
The devices affected by the vulnerabilities are:
- iPhone XS and later models
- iPad Pro 12.9-inch 2nd generation and later models, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later models, iPad Air 3rd generation and later models, iPad 6th generation and later models, and iPad mini 5th generation and later models
- Macs running macOS Monterey, Ventura, Sonoma
The two vulnerabilities were discovered and reported by security researcher Clément Lecigne of Google's Threat Analysis Team (TAG). The list of affected devices is quite large, so users are urged to update their devices immediately to stay safe. The vulnerabilities are quite serious.
Apple has not released any further information about the exploitation of zero-day vulnerabilities, but Google TAG researchers frequently uncover zero-days used in spyware against high-risk individuals such as journalists, politicians, and dissidents.

Apple has fixed 20 zero-day vulnerabilities since the beginning of 2023
The vulnerabilities CVE-2023-42916 and CVE-2023-42917 are the 19th and 20th zero-days that were fixed by Apple this year.
Since the summer, the company has patched at least 7 zero-days (9 with the current one). Some of them were used to develop the Predator spyware , as well as NSO Group's Pegasus spyware
See also: New botnet malware exploits two-zero-days to infect NVRs and Routers
Also, since the beginning of the year, Apple has fixed:
- two zero-days (CVE-2023-37450 and CVE-2023-38606) in July
- three (CVE-2023-32434, CVE-2023-32435 and CVE-2023-32439) in June
- three more zero-days (CVE-2023-32409, CVE-2023-28204 and CVE-2023-32373) in May
- two (CVE-2023-28206 and CVE-2023-28205) in April
- and another WebKit zero-day (CVE-2023-23529) in February
Zero-day vulnerabilities can have a serious impact on iPhone, iPad, and Mac users. Malicious users can exploit these vulnerabilities to gain access to devices and cause damage. This can lead to the loss of personal data, such as passwords, credit card information, and personal contacts.
Additionally, these vulnerabilities can be used to install malware on users' devices. This can lead to monitoring of user activities, theft of personal information, and loss of privacy.
See also: Pwn2Own Toronto: Over $1 million for 58 zero-days
Vulnerabilities can also affect the ' devices users. Attacks that exploit them can consume device resources, such as battery and processor, causing slow responses and application crashes.
Finally, vulnerabilities can create insecurity and anxiety among iOS users. When vulnerabilities are announced, users worry about the security of their devices and the protection of their personal data. This can affect users' trust in Apple and its corporate image.
Source: www.bleepingcomputer.com
