PSA: Safari Security Flaw 'Actively Exploited,' Update Your Apple Devices Now - MacRumors
Skip to Content

PSA: Safari Security Flaw 'Actively Exploited,' Update Your Apple Devices Now

This week, Apple released critical software updates for Safari which fix a security flaw that exists in the browser across iPhone, iPad, and Mac platforms. Here's what you need to know.

safari icon blue banner
Specifically, the platform-wide fix is for a vulnerability in Safari's WebKit engine that Apple believes may have been "actively exploited" in the wild by hackers.

The flaw, according to Apple, could allow bad actors to "process maliciously crafted web content" that may lead to "arbitrary code execution."

An additional fix that exists in the latest update for macOS Monterey, 12.5.1, relates to a vulnerability that may allow an application to "execute arbitrary code with kernel privileges."

In other words, it could allow hackers to access the deepest layer of the operating system and take complete control of the affected device. Apple says it is aware of a report that this issue may also have been actively exploited.

If you haven't updated already, it's important to do so at the earliest opportunity. The latest critical updates are as follows:

To update your iPhone or iPad, head to Settings -> General -> Software Update. To update your Mac, open System Preferences and select the Software Update preference pane.

Popular Stories

apple lock security bug vulnerability fix privacy

Apple Warns Canada's Bill C-22 Could Force Encryption Backdoors

Friday May 8, 2026 4:22 am PDT by
Apple and Meta have opposed a Canadian bill that the companies say could force them to create backdoor access to encrypted user data, should it pass through the country's parliament. Proposed by Canada's ruling Liberal Party, Bill C-22 contains provisions that could be similar ​to a UK data access provision order sent to Apple last year, depending on how they are implemented. Back in Feb...
Apple Event Logo

Apple's Next Era Begins September 1

Thursday May 7, 2026 10:36 am PDT by
Apple recently announced that Tim Cook will be stepping down as CEO later this year, after 15 years of leading the company. Effective September 1, Apple's hardware engineering chief John Ternus will become the company's next CEO, while Cook will become executive chairman of Apple's board of directors. In his new role, Apple said Cook will assist with "certain aspects" of the company,...
Instagram Feature 2

PSA: Instagram Encrypted Messaging Ends on Friday, May 8

Tuesday May 5, 2026 8:24 am PDT by
Instagram will remove end-to-end encryption for direct messages between users from May 8, 2026. When the date comes around, Meta will potentially be able to see the contents of all messages between users on the social media platform. Encrypting messages has been an optional feature in Instagram since 2023, but in March of this year the social media platform quietly updated a help page to say ...

Top Rated Comments

RedDeliciousPinkLady Avatar
49 months ago
And if our devices are so old that they can't reach those OS versions, we're supposed to just not use them anymore, right? It sounds like a sarcastic question, but is that actually, in the grand scheme of security, what we're supposed to be doing?
Score: 44 Votes (Like | Disagree)
49 months ago
Why does Safari always have to be updated with iOS update? Can't they just patch flaws independently?
Score: 40 Votes (Like | Disagree)
49 months ago
The flaw, according to Apple, could allow bad actors to "process maliciously crafted web content" that may lead to "arbitrary code execution."

This man has been brought in for questioning:


Attachment Image
Score: 30 Votes (Like | Disagree)
jclardy Avatar
49 months ago
If only Safari was an actual app store app and could allow updates outside of the core OS...
Score: 27 Votes (Like | Disagree)
49 months ago
Uhh is this fixed in the iOS/iPadOS/macOS 16 betas??
Score: 20 Votes (Like | Disagree)
Spaceboi Scaphandre Avatar
49 months ago

If only Safari was an actual app store app and could allow updates outside of the core OS...
Or if only iOS/iPadOS allowed other web browser engines besides WebKit so FireFox and Chrome wouldn't behave like Safari reskins.
Score: 19 Votes (Like | Disagree)