July 2023 — Rapid Security Response for WebKit zero-day (CVE-2023-37450)
Data compromised
Arbitrary code execution possible; no confirmed data theft
Technical writeup
Apple released Rapid Security Response updates for iOS, iPadOS, and macOS to patch a WebKit zero-day (CVE-2023-37450) that could allow arbitrary code execution when processing web content. Apple acknowledged the vulnerability was being actively exploited. The initial update was pulled hours later due to website access issues; a fixed version was released shortly after.
Root cause
WebKit vulnerability; actively exploited