Apple Releases Safari 15.6.1 to Fix Zero-day Flaw Exploited in the Wild

Share post:

Apple has released Safari 15.6.1 to fix a zero-day vulnerability that is tracked as CVE-2022-32893 and exploited in the wild by attackers.

Apple said the bug had been fixed through improved bounds checking.

While Apple patched the same zero-day vulnerability yesterday for macOS Monterey and iPhone/iPads, the recently released update for Safari will help fix the vulnerability in macOS Big Sur and Catalina.

The vulnerability is an out-of-bounds write issue in Webkit that allows an attacker to remotely execute code on a vulnerable device.

An out-of-bounds write vulnerability allows attackers supply input to a program that causes it to write data over the end or before the start of the memory buffer, with various adverse effects, including program crashes, data corruption, or in the worst case, remote code execution.

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited,” Apple warns.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

Hertz Data Breach Exposes Customer Information via Supply Chain Hack

Hertz has disclosed a data breach resulting from a cyberattack on its vendor, Cleo Communications, which compromised sensitive...

Google’s New Security Feature – Automatic Reboot

Google is introducing a new security feature in its latest Android update that will automatically reboot phones and...

Cybersecurity Firm Prodaft Buys Hacker Forum Accounts to Monitor Cybercriminal Activity

Swiss cybersecurity company Prodaft has initiated a program to purchase verified and aged accounts on hacking forums, aiming...

ChatGPT’s New Memory Feature Remembers Past Conversations for Personalized Interactions

OpenAI has upgraded ChatGPT with a long-term memory feature, enabling the AI to recall previous conversations and provide...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways