Apple fixes three serious bugs in iOS and macOS — update your iPhone and Mac right now

iPhone 15 Pro shown in hand
(Image credit: Tom's Guide)

Apple has once again released new emergency security updates to fix serious bugs in iOS and macOS that are being used by hackers to target iPhone and Mac users.

As reported by BleepingComputer, there are a total of three new zero-day vulnerabilities that have now been patched, bringing the total number of zero-days fixed so far this year to 16.

The first of these bugs (tracked as CVE-2023-41933) was discovered in the WebKit browser engine used in Safari while the second (tracked as CVE-2023-41991) was found in the Security framework. If exploited, these flaws could allow hackers to bypass signature validation using malicious apps or gain the ability to execute arbitrary code using their own malicious sites.

Meanwhile, the third bug (tracked as CVE-2023-41992) was found in the Kernel Framework which is used to provide APIs and support for kernel extensions and kernel-resident device drivers. By exploiting this flaw, an attacker could escalate privileges on a vulnerable iPhone or Mac.

In a security advisory, Apple explained that all three of these zero-day flaws were discovered by The Citizen Lab, though the company also revealed that they “may have been actively exploited by hackers against versions of iOS before iOS 16.7.”

Vulnerable Apple devices

Fortunately for iPhone and Mac users, Apple already fixed these three zero-day bugs with the release of iOS 16.7/17.0.1, macOS 12.7/13.6, iPadOS 16.7/17.0.1 and watchOS 9.6.3/10.0.1. Now, it’s up to you to install these emergency security updates if you have any vulnerable Apple devices.

The chances that you do are high though as both older and newer Apple devices are affected including the iPhone 8 and later, iPad mini 5th generation and later, Macs running macOS Monterey and newer and Apple Watch Series 4 and later.

As is often the case with zero-day flaws like the ones described above, Apple has yet to provide any additional details on how hackers have been using these bugs in their attacks. The reason being is that this will give the company’s users a chance to update their devices before other hackers can devise new ways to leverage these flaws in their attacks.

How to keep your iPhone and Mac safe from hackers

A padlock resting next to the Apple logo on the lid of a gold-colored Apple laptop.

(Image credit: robert coolen/Shutterstock)

Updating all of your devices may seem annoying and tedious at times but it’s the best way to stay safe from cyberattacks, malware and other threats online. This is because hackers often target users that haven’t updated their devices by creating exploits for zero-day flaws that have already been patched.

Besides keeping your devices up to date, you might also want to consider using the best Mac antivirus software for additional protection for your Mac. Sure, your Mac comes with built-in antivirus software from Apple called XProtect but just like Microsoft Defender on Windows, it sometimes misses the latest threats. Likewise, paid antivirus software often comes with extras like a VPN or password manager to help you stay safe online.

While there isn’t an iPhone equivalent of the best Android antivirus apps, Intego’s Mac antivirus software including Intego Mac Internet Security X9 and Intego Mac Premium Bundle X9  can scan an iPhone or iPad for malware when it’s connected to a Mac via USB.

Although 19 zero-day flaws may seem like a lot, it’s a good thing that Apple patches these flaws in a timely manner as some other companies will wait until after they’ve been used in a large-scale cyberattack to fix them.  

More from Tom's Guide

TOPICS
Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Latest in macOS
Mac Studio on a desk hooked up to a Studio DIsplay
Mac Studio M3 Ultra: 3 reasons to buy and 2 reasons to skip
Cyberpunk 2077 on MacBook Pro
5 great cloud gaming services for Mac that you should try right now
MacBook Prime Day
The widget you've always wanted comes to your Mac menu bar in Sequoia 15.2
Apple Magic Mouse USB-C
USB-C Mac accessories don't work with older macOS versions — this is a huge pain
How to keep to keep iCloud Drive files downloaded on your Mac
How to keep to keep iCloud Drive files downloaded on your Mac
How to access your passwords from the menu bar in macOS Sequoia
MacOS Sequoia lets you view saved passwords via the menu bar — here's how
Latest in News
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know
Choi Hyun-Wook, Hong Kyung, and Park Ji-hoon in "Weak Hero Class 1" now streaming on Netflix
This action-packed K-drama is now streaming on Netflix — and now’s the time to binge-watch before season 2