Urgent Security Patch From Apple

About the vulnerabilities
There are two vulnerabilities that are addressed in this update.
The first is an out-of-bounds write issue within the kernel itself. If exploited, this could lead to arbitrary code execution with kernel privileges. In layman’s terms, arbitrary code execution means that an attacker can make the device run whatever code they want it to. Not good. This issue is being tracked as CVE-2022-32894.
The second is an out-of-bounds write issue with WebKit. WebKit, if you’re not familiar, iis a browser engine developed in-house by Apple and used in their Safari web browser. If the browser processes malicious web content, it could also lead to arbitrary code execution. Again, not good. This issue is being tracked as CVE-2022-32893 and WebKit Bugzilla: 243557
How to update
To update your iPhone, iPad, or Apple Watch go to Settings > General > Software Update. Make sure you’re connected to Wi-Fi and your device is plugged into power.
To update your Mac, go to the Apple icon in the top left corner of your screen, click About This Mac, and then click Software Update.
Potential impact
Apple says in their release that they’re “aware of a report that this issue may have been actively exploited.” While they don’t say exactly how, by who, or how mature the exploit is, it’s safe to say that any vulnerability that allows arbitrary code to be run on a device should be remediated as quickly as possible. A potential attacker could leverage these vulnerabilities for an array of purposes. In previous iterations, the infamous spyware tool Pegasus used memory corruption vulnerabilities in WebKit and the kernel to secretly jailbreak the iOS device and install the surveillance software. It’s unclear whether or not these vulnerabilities have been used in newer versions of Pegasus, but one starts to wonder how and where they’re being used.
TL;DR. WebKit and kernel bugs are bad. Update ASAP.
Keep reading

May 18, 2026
Why AI-First Development Is Going to Cost You More in the Long Run
There’s a narrative taking hold right now that goes something like this: AI can write all the code, you don’t need as many developers, and the ones you do keep just need to be fast with a prompt. Fire your senior engineers. Hire a junior and an AI subscription. Ship ten times faster at a fraction of the cost.

Jul 18, 2025
Securing the AI Integration Landscape
Let’s talk about the elephant in the server room: those legacy systems quietly running critical parts of your business are becoming serious security liabilities.

May 16, 2025
Implementing Access Control Best Practices in CyberSecurity
When we talk about security in software development or system architecture, the conversation usually centers around firewalls, encryption, or penetration tests.