Apple security update fixes new iOS zero-day used to hack iPhones
In security updates released today, Apple has fixed the tenth zero-day vulnerability since the start of the year, with this latest one actively used in attacks against iPhones.
The vulnerability was disclosed in security bulletins released today for iOS/iPadOS 15.7.2, Safari 16.2, tvOS 16.2, and macOS Ventura 13.1, with Apple warning that the flaw "may have been actively exploited" against previous versions.
The bug (CVE-2022-42856) is a type confusion issue in Apple's Webkit web browser browsing engine.
References:
https://support.apple.com/en-us/HT213516
https://support.apple.com/en-us/HT213531