Apple has released some emergency security updates for two zero-day vulnerabilities that were actively used in attacks against older iPhones and certain Apple Watch and Apple TV models.

"Apple is aware that this issue may have been exploited in versions of iOS prior to iOS 16.7.1," the company said.
The two vulnerabilities, CVE-2023-42916 and CVE-2023-42917, were found in the WebKit browser engine, developed by Apple and used by the company's Safari web browser (across all platforms, including macOS, iOS, iPadOS).
See also: Google fixes new zero-day vulnerability in Chrome
They can allow attackers to gain access to sensitive data and execute code using special websites designed to exploit out-of-bounds and memory corruption bugs on unpatched devices.
Apple has addressed zero-day vulnerabilities affecting older iPhones and other devices, releasing iOS 16.7.3, iPadOS 16.7.3, tvOS 17.2, and watchOS 10.2.
The company says the bugs were also fixed on the following list of devices:
- iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
- Apple TV HD and Apple TV 4K (all models)
- Apple Watch Series 4 and later
The vulnerabilities were discovered and reported by Clément Lecigne , a security researcher from Google 's Threat Analysis Team (TAG) .
Apple has not provided details about the exploitation of the vulnerabilities and the type of attacks.
See also: Apple: Fixes zero-day bug that allows iPhone, iPad and Mac to be compromised
Since the beginning of the year, Apple has fixed 20 zero-day vulnerabilities that have been used in attacks:
- two zero-days (CVE-2023-42916 and CVE-2023-42917) in November
- two zero-days (CVE-2023-42824 and CVE-2023-5217) in October
- five zero-days (CVE-2023-41061, CVE-2023-41064, CVE-2023-41991, CVE-2023-41992 and CVE-2023-41993) in September
- two zero-days (CVE-2023-37450 and CVE-2023-38606) in July
- three zero-days (CVE-2023-32434, CVE-2023-32435 and CVE-2023-32439) in June
- three zero-days (CVE-2023-32409, CVE-2023-28204 and CVE-2023-32373) in May
- two zero-days (CVE-2023-28206 and CVE-2023-28205) in April
- and another WebKit zero-day (CVE-2023-23529) in February

Zero-day vulnerabilities can have a serious impact on users . Malicious users can exploit these vulnerabilities to gain ' devices users and cause damage. This can lead to the loss of personal data, such as passwords, credit card information, and personal contacts.
Additionally, these vulnerabilities can be used to install malware on devices users' This can lead to monitoring of user activities, theft of personal information, and loss of privacy.
See also: Pwn2Own Toronto: Over $1 million for 58 zero-days
Vulnerabilities can also affect the performance of users' devices. Attacks that exploit them can consume device resources, such as battery and processor, causing slow responses and application crashes.
Finally, vulnerabilities can users iOS. When vulnerabilities are announced, users worry about the security of their devices and the protection of their personal data. This can affect users' trust in Apple and its corporate image.
Source: www.bleepingcomputer.com
