PSA: Safari Security Flaw 'Actively Exploited,' Update Your Apple Devices Now - MacRumors
Skip to Content

PSA: Safari Security Flaw 'Actively Exploited,' Update Your Apple Devices Now

This week, Apple released critical software updates for Safari which fix a security flaw that exists in the browser across iPhone, iPad, and Mac platforms. Here's what you need to know.

safari icon blue banner
Specifically, the platform-wide fix is for a vulnerability in Safari's WebKit engine that Apple believes may have been "actively exploited" in the wild by hackers.

The flaw, according to Apple, could allow bad actors to "process maliciously crafted web content" that may lead to "arbitrary code execution."

An additional fix that exists in the latest update for macOS Monterey, 12.5.1, relates to a vulnerability that may allow an application to "execute arbitrary code with kernel privileges."

In other words, it could allow hackers to access the deepest layer of the operating system and take complete control of the affected device. Apple says it is aware of a report that this issue may also have been actively exploited.

If you haven't updated already, it's important to do so at the earliest opportunity. The latest critical updates are as follows:

To update your iPhone or iPad, head to Settings -> General -> Software Update. To update your Mac, open System Preferences and select the Software Update preference pane.

Popular Stories

macOS Tahoe and iPhone

Anthropic's AI to Help Apple Find iOS, macOS, and Safari Vulnerabilities

Wednesday April 8, 2026 1:00 pm PDT by
Anthropic on Tuesday announced Project Glasswing, a new initiative that will enable tech companies to use its new AI model Mythos Preview to find and fix security vulnerabilities or weaknesses across operating systems and web browsers. Mythos Preview has already found thousands of zero-day vulnerabilities, including some in every major operating system and web browser, according to...
Apple Event Logo

Apple Just Released a New Accessory

Monday May 4, 2026 8:13 am PDT by
Apple today released a new Pride Edition Sport Loop for the Apple Watch. The band features a rainbow design with 11 colors of woven nylon yarns. The new Pride Edition Sport Loop is available to order now on Apple.com and in the Apple Store app in 40mm, 42mm, and 46mm sizes, and it will be available at Apple Store locations starting later this week. In the U.S., the band costs $49. There...
iOS 26

Apple Says iOS 26.5 Adds Three New Features to Your iPhone

Tuesday May 5, 2026 7:36 am PDT by
iOS 26.5 includes three new features for iPhones, according to Apple's release notes for the update, which is expected to be released next week. As discovered during beta testing, iOS 26.5 enables end-to-end encryption for RCS messaging between iOS and Android devices. Apple says this security upgrade is limited to supported carriers around the world and will continue to roll out....

Top Rated Comments

RedDeliciousPinkLady Avatar
49 months ago
And if our devices are so old that they can't reach those OS versions, we're supposed to just not use them anymore, right? It sounds like a sarcastic question, but is that actually, in the grand scheme of security, what we're supposed to be doing?
Score: 44 Votes (Like | Disagree)
49 months ago
Why does Safari always have to be updated with iOS update? Can't they just patch flaws independently?
Score: 40 Votes (Like | Disagree)
49 months ago
The flaw, according to Apple, could allow bad actors to "process maliciously crafted web content" that may lead to "arbitrary code execution."

This man has been brought in for questioning:


Attachment Image
Score: 30 Votes (Like | Disagree)
jclardy Avatar
49 months ago
If only Safari was an actual app store app and could allow updates outside of the core OS...
Score: 27 Votes (Like | Disagree)
49 months ago
Uhh is this fixed in the iOS/iPadOS/macOS 16 betas??
Score: 20 Votes (Like | Disagree)
Spaceboi Scaphandre Avatar
49 months ago

If only Safari was an actual app store app and could allow updates outside of the core OS...
Or if only iOS/iPadOS allowed other web browser engines besides WebKit so FireFox and Chrome wouldn't behave like Safari reskins.
Score: 19 Votes (Like | Disagree)