Make Sure to Update: iOS 18.1.1 and macOS Sequoia 15.1.1 Fix Actively Exploited Vulnerabilities

The iOS 18.1.1, iPadOS 18.1.1, and macOS Sequoia 15.1.1 updates that Apple released today address JavaScriptCore and WebKit vulnerabilities that Apple says have been actively exploited on some devices.

bug security vulnerability issue fix larry
With the JavaScriptCore vulnerability, processing maliciously crafted web content could lead to arbitrary code execution. The WebKit vulnerability had the same issue with maliciously crafted web content, and it could lead to a cross site scripting attack.

Apple says that it is aware of reports that these two issues may have been actively exploited on Intel-based Mac systems. While the vulnerabilities are only known to have impacted older Macs, other devices are vulnerable to attack because they have the same security flaws.

For that reason, it is a good idea to update your devices to the latest software as soon as possible.

Related Forums: iOS 18, iPadOS 18, macOS Sequoia

Popular Stories

iphone 17 models

No iPhone 18 Launch This Year, Reports Suggest

Thursday January 1, 2026 8:43 am PST by
Apple is not expected to release a standard iPhone 18 model this year, according to a growing number of reports that suggest the company is planning a significant change to its long-standing annual iPhone launch cycle. Despite the immense success of the iPhone 17 in 2025, the iPhone 18 is not expected to arrive until the spring of 2027, leaving the iPhone 17 in the lineup as the latest...
duolingo ad live activity

Duolingo Used iPhone's Dynamic Island to Display Ads, Violating Apple Design Guidelines

Friday January 2, 2026 1:36 pm PST by
Language learning app Duolingo has apparently been using the iPhone's Live Activity feature to display ads on the Lock Screen and the Dynamic Island, which violates Apple's design guidelines. According to multiple reports on Reddit, the Duolingo app has been displaying an ad for a "Super offer," which is Duolingo's paid subscription option. Apple's guidelines for Live Activity state that...
Clicks Communicator Feature

'Clicks Communicator' Unveiled — Will You Carry This With Your iPhone?

Friday January 2, 2026 6:35 am PST by
The company behind the BlackBerry-like Clicks Keyboard accessory for the iPhone today unveiled a new Android 16 smartphone called the Clicks Communicator. The purpose-built device is designed to be used as a second phone alongside your iPhone, with the intended focus being communication over content consumption. It runs a custom Android launcher that offers a curated selection of messaging...
Low Cost MacBook Feature A18 Pro

Low-Price 12.9-Inch MacBook With A18 Pro Chip Reportedly Launching Early This Year

Friday January 2, 2026 9:08 am PST by
Apple plans to introduce a 12.9-inch MacBook in spring 2026, according to TrendForce. In a press release this week, the Taiwanese research firm said this MacBook will be aimed at the entry-level to mid-range market, with "competitive pricing." TrendForce did not share any further details about this MacBook, but the information that it shared lines up with several rumors about a more...
Low Cost A18 Pro MacBook Feature Pink

Apple's 2026 Low-Cost A18 Pro MacBook: What We Know So Far

Friday January 2, 2026 4:33 pm PST by
Apple is planning to release a low-cost MacBook in 2026, which will apparently compete with more affordable Chromebooks and Windows PCs. Apple's most affordable Mac right now is the $999 MacBook Air, and the upcoming low-cost MacBook is expected to be cheaper. Here's what we know about the low-cost MacBook so far. Size Rumors suggest the low-cost MacBook will have a display that's around 13 ...
Apple Fitness Plus hero

Apple Announces New Fitness+ Workout Programs, Strava Challenge, and More

Friday January 2, 2026 6:43 am PST by
Apple today announced a number of updates to Apple Fitness+ and activity with the Apple Watch. The key announcements include: New Year limited-edition award: Users can win the award by closing all three Activity Rings for seven days in a row in January. "Quit Quitting" Strava challenge: Available in Strava throughout January, users who log 12 workouts anytime in the month will win an ...
govee floor lamp

CES 2026: Govee Announces New Matter-Connected Ceiling and Floor Lights

Sunday January 4, 2026 5:00 am PST by
Govee today introduced three new HomeKit-compatible lighting products, including the Govee Floor Lamp 3, the Govee Ceiling Light Ultra, and the Govee Sky Ceiling Light. The Govee Floor Lamp 3 is the successor to the Floor Lamp 2, and it offers Matter integration with the option to connect to HomeKit. The Floor Lamp 3 offers an upgraded LuminBlend+ lighting system that can reproduce 281...

Top Rated Comments

ignatius345 Avatar
15 months ago
Whatever happened to those Rapid Security Response patches they were supposed to be able to deploy quickly? Are those being used? I see so many urgent system updates, but I can't remember getting a Rapid Security Response thing automatically.
Score: 20 Votes (Like | Disagree)
TheDailyApple Avatar
15 months ago
Do these vulnerabilities affect iOS 17.x.x and macOS 14.x.x?
Score: 11 Votes (Like | Disagree)
Yvan256 Avatar
15 months ago
And yet, ads on iOS can open a browser without our authorization if we touch anywhere on their full-screen videos, or touch one pixel outside their tiny 16×16 pixels "close" button.

Apple really needs to take over the ads with their own standard interface layered on top of the ads, and prompt us if we really want to open a URL in the browser.
Score: 8 Votes (Like | Disagree)
Lizzard899 Avatar
15 months ago
They didnt fix any bugs....I feel like they just pushed it out for Thanksgiving. IOS 18 has been a mess. Messed up icloud storage (doesn't collabrate the correct number), issues with messages app where messages show up as group text when its only 1 single text between me and 1 other person. The list goes on and on. I bet the notes app isn't fixed either
Score: 7 Votes (Like | Disagree)
winxmac Avatar
15 months ago

Whatever happened to those Rapid Security Response patches they were supposed to be able to deploy quickly? Are those being used? I see so many urgent system updates, but I can't remember getting a Rapid Security Response thing automatically.
iOS 16 was the only major version that had rapid security response
Score: 4 Votes (Like | Disagree)
decafjava Avatar
15 months ago

They didnt fix any bugs....I feel like they just pushed it out for Thanksgiving. IOS 18 has been a mess. Messed up icloud storage (doesn't collabrate the correct number), issues with messages app where messages show up as group text when its only 1 single text between me and 1 other person. The list goes on and on. I bet the notes app isn't fixed either
Not supposed to I understand, just plug a vulnerability.
Score: 4 Votes (Like | Disagree)