Apple fixes urgent zero-day flaw with iOS 17.3 — update your iPhone right now
Patch your Mac too!
After Google patched its first zero-day flaw this year, Apple has now released security updates to address a serious vulnerability that impacts iPhones, Macs and even Apple TVs.
As reported by BleepingComputer, Cupertino’s first zero-day flaw of 2024 (tracked as CVE-2024-23222) is a WebKit confusion issue that can be exploited by hackers to execute arbitrary code on impacted Apple devices. This can only occur once an attacker tricks unsuspecting iPhone or Mac users into opening a malicious site on their devices though.
In a security notice on its site, Apple explains that it is “aware of a report that this issue may have been exploited” by attackers. Surprisingly though, the company has not attributed the discovery of this new zero-day to a particular security researcher yet.
Fortunately, Apple has fixed this flaw with improved checks in iOS 16.7.5 and later, iPadOS 16.7.5 and later, macOS Monterey 12.7.3 and higher and in tvOS 17.3 and higher. If you own one of the impacted devices, you need to install these new security updates as soon as possible to avoid falling victim to any attacks exploiting this vulnerability.
Impacted Apple devices
As WebKit is Apple’s own browser engine that powers Safari, Mail, the App Store and many other macOS and iOS apps, the list of devices impacted by this zero-day is quite extensive.
For instance, the best iPhones from the iPhone XS on are vulnerable as is the iPad Pro 12.9-inch 2nd generation and later, the iPad Pro 10.5 inch, the iPad Pro 11-inch 1st generation and later, the iPad Air 3rd generation and later, the iPad 6th generation and later and the iPad mini 5th generation and later. When it comes to the best MacBooks and other Apple computers, Macs running macOS Monterey and later are impacted too as are all Apple TV HD and Apple TV 4K models.
Just like with previous Apple zero-days, this one will likely only be used in targeted attacks against high-profile individuals like politicians, journalists and business owners. Still though, vulnerabilities like this one could be used against ordinary people which is why you should update your Apple devices as soon as possible.
Sign up to get the BEST of Tom's Guide direct to your inbox.
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
How to keep your iPhone and Mac safe from hackers
When it comes to keeping your Apple devices protected, the first and most important thing you can do is to install new updates when they become available. Besides exciting new features like Stolen Device Protection, these updates also contain important security fixes.
While Macs ship with Apple’s own antivirus software in the form of XProtect, you should also consider using the best Mac antivirus software alongside it for additional protection. As for your iPhone, there’s no equivalent to the best Android antivirus apps for iOS due to the company’s own restrictions on malware scanning. However, both Intego Mac Premium Bundle X9 and Intego Mac Internet Security X9 can scan an iPhone or iPad for malware when they’re connected to a Mac via a USB cable.
Given that Apple is open to working with security researchers from all sorts of different companies (Google included) to find flaws in its products, this likely won’t be the last zero-day vulnerability we see the company patch this year. In fact, last year, Apple patched a total of 20 zero-day flaws.
More from Tom's Guide
Anthony Spadafora is the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to password managers and the best way to cover your whole home or business with Wi-Fi. Before joining the team, he wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home.