Apple has confirmed that two weeks ago it fixed a vulnerability in the iPhone security system, which was actively used by cybercriminals. According to TechCrunch, an Apple competitor helped identify the vulnerability.
Released on November 30, iOS 16.1.2 is a "major security update" that all phones released after the iPhone 8 received.
Apple said the update fixed a WebKit vulnerability. It's the browser engine on which Safari and other apps run. The vulnerability allowed attackers to run malicious code on users' devices. Apple said that information about the problem was provided by Google's Threat Analysis Group, which is dedicated to protecting the company's products and users from cyber-threats, spyware and cyber-attacks.
Vulnerabilities in WebKit are often exploited when visiting malicious sites, both when using the Safari browser and when using a browser built into the app. Attackers quite often try to exploit the flaws found in WebKit to "hack" users' operating systems and gain access to sensitive data. Vulnerabilities in WebKit can be used in conjunction with other vulnerabilities to crack the layered security of Apple devices.
The company said Tuesday that the vulnerability was being exploited in versions of iOS released before iOS 15.1 (in October 2021). For those who haven't yet upgraded their phones to iOS 16, Apple has released an update to iOS and iPadOS 15.7.2 that removes some flaws in iPhone 6s and later models, as well as flaws in iPad models.
The vulnerability was named CVE-2022-42856 or WebKit 247562. It is still unknown why Apple did not provide details about it within two weeks of its removal. Neither Apple nor Google has commented on the situation. Apple has since released an update to iOS 16.2, which includes enhanced end-to-end encryption in iCloud and other new features.






