Skip to content
Menu
  • Home
  • Tips
  • Security
  • Hardware
    • Mac
    • iPhone
    • iPad
    • Apple Watch
    • Vision Pro
    • Apple TV
    • Accessories
  • Software
    • macOS
    • iOS
    • iPadOS
    • visionOS
    • watchOS
    • tvOS
    • Apps
  • Buying Guides
    • How to choose a Mac laptop
    • How to choose a desktop Mac
    • Laptop vs desktop – how to decide
    • How to choose an Apple Watch
  • About
  • RSS

Apple updates macOS, iPadOS, iOS, tvOS with critical security updates

Posted on July 25, 2023July 25, 2023
Share on Social Media
x facebook linkedin reddit email

Apple has released a slew of software updates across its product portfolio and addressed a long list of security vulnerabilities.  iOS 16.6, iPadOS 16.6, macOS Ventura 13.5, watchOS 9.6, tvOS 16.6,  iOS 15.7.8, iPadOS 15.7.8, macOS Monterey 12.6.8, and macOS Big Sur 11.7.9 have all been updated.

The range of fixes is extensive. One of the vulnerabilities could allow an app to modify a sensitive kernel state – something Apple says may have been actively exploited already. Apple also says a WebKit vulnerability may have been actively exploited. This was already patched with a Rapid Security Response (iOS 16.5.1 (c) and ‌macOS Ventura‌ 13.4.1 (c)). If you allow automatic software updates you may already be protected from this issue.

Four reasons you should enable automatic software updates

Here’s the full list of patched vulnerabilities. You can look up the full data for each reported vulnerability in the Common Vulnerabilities and Exposures (CVE) database by entering the CVE number for each listed vulnerability.

TypeForImpactCVE
KerneliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.12023-38606
WebKitiPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterProcessing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited2023-37450
Apple Neural EngineDevices with Apple Neural Engine: iPhone 8 and later, iPad Pro (3rd generation) and later, iPad Air (3rd generation) and later, and iPad mini (5th generation)An app may be able to execute arbitrary code with kernel privileges2023-38136 and 2023-38580
Find MyiPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and lateAn app may be able to read sensitive location information2023-32416
KernelPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to execute arbitrary code with kernel privileges2023-32734 and
2023-32441 and
2023-38261 and
2023-38424 and 2023-38425
KerneliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.12023-38606
KerneliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to execute arbitrary code with kernel privileges023-32381 and
2023-32433 and 2023-35993
KerneliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterA user may be able to elevate privileges2023-38410
KerneliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterA remote user may be able to cause a denial-of-service2023-38603
libxpciPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to gain root privileges2023-38565
libxpciPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to cause a denial-of-service2023-38593
NSURLSessioniPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterAn app may be able to break out of its sandbox2023-32437
WebKitiPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterA website may be able to bypass Same Origin Policy2023-38572
WebKitiPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterProcessing web content may lead to arbitrary code execution2023-38594 and 2023-38595 and
2023-38600
WebKitiPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterProcessing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited2023-37450
WebKit Process ModeliPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterProcessing web content may lead to arbitrary code execution2023-38597
WebKit Web InspectoriPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and laterProcessing web content may disclose sensitive information2023-38133
Anthony Caruana

Anthony is the founder of Australian Apple News. He is a long-time Apple user and former editor of Australian Macworld. He has contributed to many technology magazines and newspapers as well as appearing regularly on radio and occasionally on TV.

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X

Related

No authorisation is provided for the content on the site to be scraped or otherwise used for the training of machine learning, AI models or any other reuse without the express written permission of the site owner.

©2025 | WordPress Theme by Superb WordPress Themes