Apple releases iOS 16.6 to patch several software flaws some of which have been actively exploited

In this article (5)
This patch is heading to iPhone 8 and later, iPad Pro (3rd generation) and later, iPad Air (3rd generation) and later, and iPad mini (5th generation). A vulnerability on the Find My app could allow sensitive location information to be divulged via an app. This patch will be available to the iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.
Several patches for the Kernel are part of the update. This is the core part of an operating system. With one flaw, Apple says it is aware of reports that the vulnerability has been actively exploited on versions of iOS released before iOS 15.7.1. With this vulnerability, “an app may be able to modify sensitive kernel state” allowing the attackers to manipulate how the operating system runs.
Questions & Answers
Q.Which specific iPhone and iPad models are receiving the iOS 16.6 and iPadOS 16.6 updates?
Which specific iPhone and iPad models are receiving the iOS 16.6 and iPadOS 16.6 updates?
The updates are for iPhone 8 and later, iPad Pro (3rd generation) and later, iPad Air (3rd generation) and later, and iPad mini (5th generation). The Find My patch has slightly broader support for some models.
Q.What is the most serious threat addressed by these software updates?
What is the most serious threat addressed by these software updates?
Several serious threats are addressed, including one where an app might execute arbitrary code with kernel privileges. Also, some vulnerabilities for WebKit and Kernel have been actively exploited, potentially allowing manipulation of the operating system or root access.
Q.What other Apple device updates were released alongside iOS 16.6 and iPadOS 16.6?
What other Apple device updates were released alongside iOS 16.6 and iPadOS 16.6?
Other updates available include watchOS 9.6, macOS 13.5, and tvOS 16.6. These updates were released on the same day as the iOS and iPadOS patches.
Q.What could an attacker potentially do with a vulnerability in the Apple Neural Engine?
What could an attacker potentially do with a vulnerability in the Apple Neural Engine?
An attacker might be able to execute arbitrary code with kernel privileges. This means they could run any command on a targeted iPhone or iPad, gaining significant control over the device.
Reader pulse
Will retailers prioritise this iOS 16.6 update?
20,505 votes so far