These iPhones and iPads just got an emergency security patch — update now

A hand holding a brand-new iPhone 6 over an Apple Magic Mouse and iMac keyboard.
(Image credit: DenPhotos/Shutterstock)

If you've been hanging on to your iPhone, iPad, or Mac for a few years, take heed: Apple has patched older iPhones, as well as macOS Catalina, to fix three security vulnerabilities that have been exploited by hackers "in the wild."

Handsets ranging from the iPhone 5s through the iPhone 6 Plus, as well as the first two iPad Air models, the iPad Mini 3 and the sixth-generation iPod Touch can now upgrade to iOS 12.5.5.

There's also a security patch (the ninth without a "point" upgrade) for macOS 10.15.7 Catalina, benefiting users of iMacs, MacBooks and Mac Minis released from 2012 to 2014 that can't upgrade to macOS 11 Big Sur.

However, there's still no apparent fix for another flaw affecting all versions of macOS up through the most recent version of Big Sur.

To update your iPhone, tap through Settings > General > Software Update. To update your Mac, click the Apple icon in the top left corner, then System Prefrences or Software Update and follow the prompts. 

Catching up with newer devices

This new iOS 12 update fixes two flaws, catalogued as CVE-2021-30858 and CVE-2021-30860, that were first patched last week in newer iPhones with the release of iOS 14.8 and in macOS Big Sur with an upgrade to 11.6.

The latter vulnerability has been used by clients of an Israeli spyware firm called NSO to spy on dissidents, diplomats and political figures, especially in the Middle East. The other flaw has also been exploited, but there's been no public disclosure of who was hacking whom or even who discovered the vulnerability.

iOS 12.5.5 also fixes a new flaw, CVE-2021-30869, that permits "a malicious application" to run its own code on a device, according to Apple's security bulletin. That's thanks to "a type confusion issue" in XNU, the kernel at the heart of all current Apple operating systems including iOS and macOS.

Credit for the discovery of this vulnerability was given to Erye Hernandez and Clément Lecigne of the Google Threat Analysis Group, plus Ian Beer of Google Project Zero. 

As with the other two flaws, Apple states that it "is aware of reports that an exploit for this issue exists in the wild." It's not saying any more.

However, Shane Huntley of Google's Threat Analysis Group said on Twitter that the flaw was used alongside another flaw that targeted the rendering engine powering Apple's Safari browser. He added that more information would be released toward the end of next month.

The fix for CVE-2021-30869 is the entirety of the new patch for macOS Catalina. The fact that the flaw hasn't been patched in macOS Big Sur or iOS 15 indicates that it doesn't exist or is impossible to exploit on those newer operating systems.

Apple has been continuing to supply iPhones and iPads from 2013 and 2014 — the same age as the patched older Macs — with security updates for iOS 12 despite its general policy of not supporting mobile devices more than five years old. 

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Windows
240 million Windows 10 users are vulnerable to six different hacker exploits — protect yourself now
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Latest in Tech
Casetify Bounce Suitcase
I ditched my Away Carry-On for a bright red suitcase made by a phone case brand, and I was shocked by how much I liked it
Columbia Sportswear and Intuitive Machines partnership
Columbia Sportswear’s UV-blocking technology just landed on the moon, and I spoke to the materials scientist who designed it
iPhone 16e review.
What Tom’s Guide tested this week — the iPhone 16e is the most polarizing phone of the year
A split screen photo showing a coffee grinder on one side and a smart watch on the other
What Tom’s Guide tested this week: Sony, OnePlus, Corsair and more
A split screen image showing an instant camera on the left and a Dyson vacuum on the right
What Tom’s Guide tested this week: Expert reviews of Dyson, Insta360 and more
A composite of Soundcore Space One Pro headphones and Sony ZV-1F vlogging camera
What Tom’s Guide tested this week: 5 products that won our expert reviewers’ hearts
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones