Apple fixes zero-day security flaws on older iPhones — update now

iPhone
(Image credit: Apple)

If you’ve got an older iOS device like an iPhone 6 or iPad Air, you may want to fire it up and download Apple’s latest update, iOS 12.5.4. 

Apple's security bulletin says the update squashes two serious security flaws related to the Safari browser, or more specifically the page-rendering engine which runs it, called WebKit. Both flaws are considered "zero-day" flaws because they may already have been exploited in the wild, i.e. used by hackers to attack iPhone users.

The first zero-day flaw, listed as CVE-2021-30761, involves a memory-corruption issue in WebKit. The second, CVE-2021-30762, lets malicious code invade WebKit's memory space after WebKit has freed up some memory — a "use after free" bug in information-security parlance.

Both flaws were discovered by "an anonymous researcher," said Apple, and both could let "maliciously crafted web content" run code on an iOS device. In other words, the flaws might let a poisoned website install and run malware on an iPhone. The flaws appear to be unique to iOS 12.

A third flaw, CVE-2021-30737, which does not appear to have been used in active attacks, involves a memory-corruption issue in ASN.1, software used to encrypt and decrypt secure communications. 

The same flaw, whose discovery was credited to "xerub," was fixed on newer iPhones with iOS 14.6 in May. An attacker could use this flaw to make an iOS device load and run malware after reading a maliciously-crafted security certificate.

Old phones still matter

Apple is patching these flaws on all devices running iOS 12, which includes the iPhone 5s (released in 2013), iPhone 6 and 6 Plus (both released in 2014). These devices didn’t get an upgrade to iOS 13, so they’re still on a point release of iOS 12. 

Apple does keep pushing security updates for old devices though, keeping them safe even if they’re denied more modern features. You'd be hard pressed to find an eight-year-old Android phone that still gets security updates.

Millions of people could nevertheless be affected by these flaws. Maybe they're still using older iPhones, or have old devices knocking around that are used occasionally. That old iPad you use for YouTube, or those old iPhones you’ve given to your kids, could be vulnerable.

How to update to iOS 12.5.4

To update your iOS device, head to the Settings menu, look for “General” and tap “Software update,” which will find the new patch and download it for you. You might want to make sure you’ve made a full backup of your device first just in case.

TOPICS

Ian has been involved in technology journalism since 2007, originally writing about AV hardware back when LCDs and plasma TVs were just gaining popularity. Nearly 15 years on, he remains as excited as ever about how tech can make your life better. Ian is the editor of T3.com but has also regularly contributed to Tom's Guide.

Read more
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
Google Pixel 9 held in the hand.
Google just fixed a zero-day kernel flaw used by hackers and 47 other vulnerabilities — update your Android phone right now
iOS 18 home screen customization features
Apple will no longer allow users to downgrade from iOS 18.3 — here’s why
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know
Choi Hyun-Wook, Hong Kyung, and Park Ji-hoon in "Weak Hero Class 1" now streaming on Netflix
This action-packed K-drama is now streaming on Netflix — and now’s the time to binge-watch before season 2
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)