Apple Patches Dozens of WebKit Flaws That Could Let Attackers Crash or Spy on Your iPhone and Mac
A wave of security fixes landed for iPhones and Macs, closing holes in the browser engine that powers Safari. Some bugs were serious enough to let criminals steal data or break out of the software's built-in safety walls.

Key points
- Apple released security updates for macOS and iOS patching dozens of flaws in WebKit, the engine that runs the Safari browser.
- The bugs could allow attackers to crash Safari, corrupt device memory, leak private data, or escape the sandbox (a protective barrier that keeps software isolated from the rest of the device).
- No single criminal group has been named, but unpatched devices remain at risk until users update.
- The fixes apply to both iPhones and Mac computers running Apple software.
What actually happened?
Apple shipped fresh security updates for iPhones and Macs, and the headline number is a long one: dozens of flaws patched in a single round of fixes, most of them sitting inside WebKit, the engine under the bonnet of Safari.
WebKit is the piece of software that reads a web page and turns it into what you see on screen. Because it handles untrusted content from the internet all day long, it is one of the most attractive targets for attackers. A flaw there can mean a criminal builds a booby-trapped web page and waits for you to visit it.
The bugs, first reported by SecurityWeek, covered a wide range of harm. Some could crash Safari outright. Others could corrupt memory, which is the temporary working space a device uses to run apps, causing unpredictable and dangerous behaviour. A further set could leak sensitive data sitting in that memory, private snippets a web page should never be able to read. The most serious category allowed a sandbox escape, meaning an attacker could break out of the restricted zone where Safari is meant to be contained and reach other parts of the operating system. One class of bug could let criminals pull data off the device entirely.
Should iPhone and Mac users be worried?
If your device is updated, no. If it is not, yes.
The failure mode here is straightforward: you visit a web page built to trigger one of these bugs, Safari processes it, and something bad happens before you have clicked a single link. That is the nature of browser-engine vulnerabilities. No download required, no fake login page, nothing obviously suspicious.
Apple has not said any of these specific bugs were actively exploited in the wild before the patch arrived, which is a small comfort. But the gap between a patch being published and attackers reverse-engineering it to build attacks is measured in days, sometimes hours. Waiting is not a strategy.
What should you do right now?
Update. That is the whole job.
On an iPhone or iPad: go to Settings, then General, then Software Update. On a Mac: go to System Settings, then General, then Software Update. If Apple says an update is available, install it today, not this weekend.
If you manage devices for a business, your MDM platform (Mobile Device Management, the software companies use to push settings to company phones and laptops remotely) should be kicking these updates out automatically. Check that it is actually doing so, rather than assuming.
One thing the post-mortem will say, if this ever becomes an incident: the patch was available, and the device had not been updated.
Update your devices now. That sentence covers the whole operational takeaway.



