Apple Pushes Emergency Fixes for Two Flaws Already Being Used to Attack iPhones and Macs

Two previously unknown security holes, one in the heart of Apple's operating system and one in its browser engine, are being actively exploited. Every iPhone, iPad, and Mac owner should update today.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Extreme close-up of a glowing smartphone screen showing a software update progress bar, deep shadows around the device, cool blue-white light from the screen il
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Apple released emergency security updates on Wednesday covering iOS 15.6.1 and macOS Monterey 12.5.1.
  • CVE-2022-32894, a kernel flaw (the kernel being the core software that controls everything a device does), lets a malicious app take full control of an Apple device.
  • CVE-2022-32893, a flaw in WebKit (the engine powering Safari and every other browser on iOS), lets a booby-trapped webpage silently run harmful code on a device.
  • Both flaws were reported to Apple by an anonymous researcher and confirmed to be under active attack at the time of disclosure.
  • Rachel Tobac, CEO of SocialProof Security, advised journalists and activists targeted by nation states to update immediately.

Apple rarely uses the word "urgent." This week it did.

The company pushed out patches for iPhones and Macs after confirming that attackers had already found and weaponised two separate software flaws. Both fixes should already be on your device.

The first hole, catalogued as CVE-2022-32894, sits inside the kernel, the low-level software that every other program on the device depends on. A flaw there is about as bad as it gets. An attacker who exploits it can run any code they like with full, unrestricted access to the device. Apple described it clinically as an "out-of-bounds write," meaning software writing data into memory regions it was never supposed to touch.

The second flaw, CVE-2022-32893, lives in WebKit, the browser engine beneath Safari and every third-party browser on iOS. We've tracked WebKit vulnerabilities in five stories since late June, including Apple's multi-component patch round on 1 July, so the pattern here isn't new. Visit the wrong webpage and an attacker can run code on your phone without you doing anything else. No download required, no password to steal.

Could this be used to spy on ordinary people?

Yes, potentially. Security experts noted that the two flaws combined could give an attacker the same depth of access that made Pegasus infamous. Pegasus is the commercial spyware built by Israeli firm NSO Group, which governments used to silently monitor journalists and activists by exploiting similar iPhone vulnerabilities. An anonymous researcher discovered both flaws, and Apple wouldn't identify who's currently using them in attacks.

The failure mode is familiar. A high-value target loads a webpage or opens an app. No warning appears. The device is owned.

For most people the risk is lower, but "lower" isn't "zero." Any future post-mortem tied to these CVEs will note that the patch was available and free.

Fix it now: go to Settings, tap General, then Software Update. Install iOS 15.6.1 on an iPhone or iPad, macOS Monterey 12.5.1 on a Mac. If you work in journalism or activism, where powerful people might want to read your messages, don't wait until tonight.

This story was originally reported by Threatpost.

Operational takeaway: Automatic updates exist for exactly this reason. Turn them on and stop relying on memory.

© 2026 Threat Vectr