iPhone Users Urged to Update to Patch 2 Zero-Days
Two zero-day vulnerabilities affecting Apple devices running iOS 15 and macOS Monterey were actively exploited and patched in August 2022. One is a kernel out-of-bounds write flaw allowing arbitrary code execution with kernel privileges (CVE-2022-32894). The other is a WebKit out-of-bounds write vulnerability enabling code execution via malicious web content (CVE-2022-32893). Apple released patches in iOS 15.6.1 and macOS Monterey 12.5.1 to address these issues. Users were urged to update immediately due to active exploitation reports.
AI Analysis
Technical Summary
Apple disclosed two zero-day vulnerabilities under active attack in August 2022 affecting iOS 15 and macOS Monterey. CVE-2022-32894 is a kernel out-of-bounds write issue fixed by improved bounds checking, allowing arbitrary code execution with kernel privileges. CVE-2022-32893 is a WebKit out-of-bounds write flaw also fixed by improved bounds checking, enabling code execution through processing malicious web content. Both vulnerabilities could allow attackers to take full control of affected devices. Patches were released in iOS 15.6.1 and macOS Monterey 12.5.1. The flaws were reported by an anonymous researcher. The WebKit bug affects Safari and all third-party browsers on iOS. The vulnerabilities raised concerns about potential Pegasus-like spyware scenarios.
Potential Impact
Successful exploitation of these vulnerabilities allows attackers to execute arbitrary code with kernel privileges (CVE-2022-32894) or through malicious web content (CVE-2022-32893), potentially leading to full device compromise. Both flaws were reported to be actively exploited in the wild at the time of disclosure, increasing the risk to users of affected Apple devices running iOS 15 or macOS Monterey.
Mitigation Recommendations
Apple has released official patches addressing these vulnerabilities in iOS 15.6.1 and macOS Monterey 12.5.1. Users should immediately update their devices to these versions to mitigate the risk. No additional vendor-recommended mitigations were specified beyond applying the updates.
iPhone Users Urged to Update to Patch 2 Zero-Days
Description
Two zero-day vulnerabilities affecting Apple devices running iOS 15 and macOS Monterey were actively exploited and patched in August 2022. One is a kernel out-of-bounds write flaw allowing arbitrary code execution with kernel privileges (CVE-2022-32894). The other is a WebKit out-of-bounds write vulnerability enabling code execution via malicious web content (CVE-2022-32893). Apple released patches in iOS 15.6.1 and macOS Monterey 12.5.1 to address these issues. Users were urged to update immediately due to active exploitation reports.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apple disclosed two zero-day vulnerabilities under active attack in August 2022 affecting iOS 15 and macOS Monterey. CVE-2022-32894 is a kernel out-of-bounds write issue fixed by improved bounds checking, allowing arbitrary code execution with kernel privileges. CVE-2022-32893 is a WebKit out-of-bounds write flaw also fixed by improved bounds checking, enabling code execution through processing malicious web content. Both vulnerabilities could allow attackers to take full control of affected devices. Patches were released in iOS 15.6.1 and macOS Monterey 12.5.1. The flaws were reported by an anonymous researcher. The WebKit bug affects Safari and all third-party browsers on iOS. The vulnerabilities raised concerns about potential Pegasus-like spyware scenarios.
Potential Impact
Successful exploitation of these vulnerabilities allows attackers to execute arbitrary code with kernel privileges (CVE-2022-32894) or through malicious web content (CVE-2022-32893), potentially leading to full device compromise. Both flaws were reported to be actively exploited in the wild at the time of disclosure, increasing the risk to users of affected Apple devices running iOS 15 or macOS Monterey.
Mitigation Recommendations
Apple has released official patches addressing these vulnerabilities in iOS 15.6.1 and macOS Monterey 12.5.1. Users should immediately update their devices to these versions to mitigate the risk. No additional vendor-recommended mitigations were specified beyond applying the updates.
Technical Details
- Classification
- {"confidence":0.66,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://threatpost.com/iphone-users-urged-to-update-to-patch-2-zero-days-under-attack/180448/","fetched":true,"fetchedAt":"2026-08-04T12:41:23.610Z","wordCount":875}
Threat ID: 6a71ddf3bf8831d539cc9793
Added to database: 08/04/2026, 12:41:23 UTC
Last enriched: 08/04/2026, 12:43:23 UTC
Last updated: 09/17/2026, 05:07:22 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.