Adobe, Microsoft, Apple Patch Dozens of Critical Flaws
Adobe, Microsoft and Apple fixed dozens of vulnerabilities, a good deal of which could compromise a computer without any user input.
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
Another Patch Tuesday has come and gone, and not only Microsoft released patches this time. Adobe and Apple got in on the action as well, and it looks like all three companies want to start the new year with as few bugs as possible. Each company fixed dozens of vulnerabilities, a good many of which could result in the compromise of a computer without any user input — and some of the exploits for those vulnerabilities are already out in the wild.
Microsoft's December Patch Tuesday addressed more than 70 flaws, the majority of which the company deemed "Critical" and involved remote code execution. That means that an hacker could exploit the flaw to install and run malware from afar, with no input from a legitimate user whatsoever. These issues affected Microsoft Windows, Office, and Internet Explorer primarily, as well as the company's Silverlight protocol. Attackers have already taken advantage of at least one vulnerability in Windows and another one in Office, so patch your systems if you haven't already, even though doing so may take a long time.
MORE: Best Antivirus Software and Apps
On the Adobe front, the Flash Player browser plugin is still a mess of vulnerabilities, and Tom's Guide recommends that you uninstall it, disable it, or at least set it to "click to run." The latest patch covers more than 70 separate issues across 10 different Flash products, including Flash Player for Google Chrome, Flash Player for Linux and AIR for Android. Adobe has rated the bugs as Critical, which, like Microsoft's ratings, means that the vulnerabilities could result in the compromise of a user's system without his or her knowledge or permission.
Apple rounds out the December patch list, with almost 40 vulnerabilities fixed in its OS X operating system. Most issues affect the El Capitan build, although some target Yosemite and Mavericks users as well. The issues run the gamut from Bluetooth to iBooks to the OS X kernel (a potentially devastating place for a security issue), and vary in severity as well. The worst could allow a remote user to compromise a Mac, whereas the milder ones might simply allow installation of malware from suspicious websites.
The stylish electronics manufacturer also released a plethora of patches for iOS, the Apple TV (tvOS), Safari and the Apple Watch (watchOS). There are dozens and dozens of fixes for the Apple peripherals, which cover everything from remote code execution in Safari to manipulating Siri to read private information on an iPhone or iPad. While there are too many fixes to detail individual cases, the bugs range from the annoying to the potentially system-compromising, and you should probably head them off at the pass before someone attempts to leverage them in the wild. Most of these devices update automatically, but if yours doesn't, you can force an update in the Settings menu.
Check the company websites if you want precise details on each flaw, but the best advice is to update your programs ASAP. Windows users can run Windows Update, which will patch all Microsoft programs. Those with Adobe software can make use of the Adobe updater program that was probably installed along with whichever of the company's products you use, although Google Chrome and Microsoft Edge and Internet Explorer 10 and 11 will update Flash by themselves. Otherwise, browse to http://get.abode.com/flashplayer. Apple users should check the App Store and Updates under the Apple log in the upper-left corner.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

Marshall Honorof was a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi.
