Share This Article
Apple has issued iOS 18.1.1, an emergency iPhone update that you should apply now. That’s because iOS 18.1.1 fixes two serious security vulnerabilities, both of which are already being used in real-life attacks.
Apple doesn’t give much information about what’s fixed in iOS 18.1.1, to give people as much time to update as possible before more attackers get hold of the details. But the iPhone maker does say the iOS 18.1.1 update “provides important security fixes and is recommended for all users.”
Tracked as CVE-2024-44308, the first issue patched in iOS 18.1.1 is a flaw in the JavaScriptCore framework that could result in code execution if the user interacts with maliciously crafted web content. “Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems,” the iPhone maker said on its support page.
The second issue patched in iOS 18.1.1, tracked as CVE-2024-44309, is a flaw in WebKit, the engine that underpins Apple’s Safari browser. If exploited, a user could fall victim to a cross-site scripting attack, which sees an attacker inject malicious code into a trusted website or application.
Again, Apple said it is aware of a report that this issue “may have been actively exploited on Intel-based Mac systems.”
Alongside iOS 18.1.1, Apple has also released iOS 17.7.2, for people with older devices or who do not want to upgrade to iOS 18 yet, fixing the same two vulnerabilities.
The US Cybersecurity and Infrastructure Agency (CISA) has also issued a warning, telling businesses and users to update to iOS 18.1.1 or iOS 17.7.2, macOS Sequoia 15.1.1, visionOS 2.2.2 and Safari 18.1.1 as soon as possible. “Apple released security updates to address vulnerabilities in multiple Apple products,” the CISA alert says.
CISA says the Apple updates are important because “a cyber threat actor could exploit some of these vulnerabilities to take control of an affected system.”
With this in mind, the agency says it encourages users and administrators to review the advisories and “apply necessary updates.”