CISA Warns of Apple macOS, iOS, tvOS, Safari, and watchOS Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has released a high-priority alert regarding a critical vulnerability affecting multiple Apple products.
The Cybersecurity and Infrastructure Security Agency (CISA) has released a high-priority alert regarding a critical vulnerability affecting multiple Apple products.
The vulnerability, identified as CVE-2022-48503 , exists in the JavaScriptCore engine and may allow attackers to execute arbitrary code by processing malicious web content. This flaw affects macOS, iOS, tvOS, Safari, and watchOS.
Originally disclosed in 2022, the vulnerability has resurfaced in active attacks, as recorded in CISA's Known Exploited Vulnerabilities (KEV) catalog. Although Apple has released patches, unpatched or end-of-life (EoL) systems remain vulnerable.
The severity of the vulnerability lies in its potential for full system compromise, including data theft and malware deployment. While no direct links to ransomware campaigns have been confirmed, the exploitation history emphasizes the need for immediate action.
Originally disclosed in 2022, the vulnerability has resurfaced in active attacks, as recorded in CISA's Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability affects Apple's core operating systems and browser. JavaScriptCore, used in Safari and other web renderings, processes dynamic web elements such as scripts and animations. Attackers can exploit this flaw through crafted web pages or email links.
Devices running older versions of iOS or macOS are particularly vulnerable if updates have not been applied. End-of-service (EoS) products are especially at risk, as they no longer receive patches from Apple.
Update to the latest vendor-patched versions immediately. Users can verify their system updates via Settings > General > Software Update. If updates are not feasible for EoL hardware, discontinue use to prevent exploitation. Network defenders should monitor for unusual JavaScript activity and enforce detection rules targeting code execution attempts.
Organizations are advised to apply mitigations or retire affected systems as per Binding Operational Directive (BOD) 22-01.
Recent data indicates a 20% increase in attacks on Apple platforms annually, highlighting the necessity of prompt patching to prevent potential breaches.
Based on reporting by Cyber Security News.
