Skip to content
E-Tailing

Apple patching a serious WebKit flaw by disseminating iOS 16.5.1 (c)

By Wei Zhang
2 min read
iOS 13.1.3
iOS 13.1.3
In this article (4)
Back on June 21st, Apple disseminated iOS 16.5.1 and iPadOS 16.5.1. But soon it was discovered that the updates had a flaw in the WebKit browser engine that could lead an attacker to create an arbitrary code execution which would allow said attacker to run any command or code on a targeted device. That is a serious problem and to top it off, Apple said that it had reports that the vulnerability was being actively exploited.
Instead of having to develop iOS 16.5.2 and iPadOS 16.5.2, Apple decided to use its Rapid Security Response feature to push out iOS 16.5.1 (a) and iPadOS 16.5.1 (a). These updates can be installed in a matter of minutes and can be quickly disseminated to Apple device users to patch a serious vulnerability such as the one that was supposed to be patched by Monday’s update. Note that we said that the update was “supposed” to patch the flaw. That’s because the updates sent out to fix the WebKit issue on Monday had issues of their own.
According to several iPhone and iPad users, the updates changed the user agent for Safari. The user agent tells server information about the device requesting content from it so the server knows what information to send out. For example, the user agent will determine whether a request to see a phone manufacturer’s website should return the U.S. site with models sold in the States priced in Dollars, or whether it should show the site created for European buyers that lists models offered on the continent with prices posted in Euros.
As a result of the issue with the user agent, iPhone, and iPad users complained that they were not able to access sites like Zoom, Facebook, and Instagram after installing iOS 16.5.1 (a) and iPadOS 16.5.1 (a). Apple, realizing that there was a problem with the updates, pulled them yesterday and even included directions on how to delete them. But if you haven’t deleted the updates, don’t worry. Apple has now released iOS 16.5.1 (c) and iPadOS 16.5.1 (c).
We said the other day that the vulnerability was too serious for Apple not to push out another patch right away, and now it has happened. To download and install the updates, go to Settings > General > Software Updates and follow the directions. Hopefully, Apple won’t be taking these updates back.

Questions & Answers

Q.

What was the initial problem with iOS 16.5.1 and iPadOS 16.5.1?

A.

These updates had a flaw in the WebKit browser engine, allowing an attacker to run arbitrary code on a targeted device. Apple reported this vulnerability was being actively exploited, making it a serious security concern.

Q.

What was the issue with the first Rapid Security Response updates, iOS 16.5.1 (a) and iPadOS 16.5.1 (a)?

A.

These updates caused problems with the user agent for Safari, preventing iPhone and iPad users from accessing sites like Zoom, Facebook, and Instagram. Apple subsequently pulled these updates.

Q.

How did Apple address the user agent issue from the Rapid Security Response updates?

A.

Apple released iOS 16.5.1 (c) and iPadOS 16.5.1 (c) to resolve the problem. They also provided directions for users to delete the previous problematic updates.

Reader pulse

Apple's quick fix:

21,536 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready