iOS 16.3. macOS 13.2 Updates Included Patches for Major Vulnerabilities Detected by Security Researcher

The security vulnerabilities could allow malicious applications to access users' personal information.

Advertisement
Written by David Delima | Updated: 24 February 2023 15:56 IST
Highlights
  • iOS 16.3 and macOS 13.2 were released in January
  • Both operating systems included patches for two major security flaws
  • Attackers could use these flaws to access users' personal information

Users who have updated to iOS 16.3 and macOS 13.2 should be safe

Photo Credit: Reuters

Apple fixed two major security vulnerabilities with iOS 16.3 and macOS 13.2 for supported iPhone, iPad and Mac models, according to details shared by a security research firm. These updates were rolled out to users last month, and came with important bug fixes and security patches. Apple has credited the researchers with finding these flaws, that allowed a remote user to bypass protections put in place by Apple and gain access to a user's personal data as well as their camera, microphone, and call history.

Security research firm Trellix explains in a blog post that Apple introduced security fixes to block the ForcedEntry security exploit used by NSO Group, creator of the nefarious Pegasus malware, in 2021. However, the firm found that these security protections could be bypassed by a remote user, and reported the flaws to Apple. 

Apple is said to have used a protocol called NSPredicateVisitor to shore up the security of its NSPredicate tool, that is used by developers to filter code.  Exploits like ForcedEntry would be able to bypass that mechanism to gain access to the user's device.

Advertisement

An attacker could use the security flaw to bypass the sandbox that prevents one app from accessing data of other apps on the device, as well as sensitive or personal information, according to the security firm. These could include messages, call logs, photos, location details, as well as smartphone hardware such as the camera and microphone. 

Advertisement

However, there appears to be no evidence that these flaws have been exploited by malicious actors. Meanwhile, users who have updated their devices to the latest version of iOS and macOS should be protected from these security flaws, according to Trellix.

Apple has also updated its release notes for iOS 16.3 and macOS 13.2, and both documents credit Trellix Senior Security Researcher Austin Emmitt with identifying two security flaws — CVE-2023-23530 and CVE-2023-23531 — on the mobile and desktop operating systems. Meanwhile, Trellix has thanked Apple for working quickly with the firm to resolve both security flaws. 

Advertisement


Is the new expensive 10th generation iPad worth buying instead of its predecessor? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, Security Flaws, iOS, macOS
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo 90 Series 5G India Launch Announced
  2. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  3. Be Dune Teen OTT Release: When, Where to Watch the Marathi Comedy Drama
  4. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  5. OpenAI Says ChatGPT Isn't Showing Ads to Paid Users
  6. Xiaomi India COO Talks About Next Redmi Note, AI, and IoT Strategy
  7. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  8. Meta's Next Mixed Reality Smart Glasses Could Be Delayed to 2027
  9. Glaciers Speed Up in Summer and Slow in Winter, New Global Map Reveals
  1. Chinese Brands Aiming to Win Users with AI Features That Apple Lacks: Report
  2. Vivo S50, Vivo S50 Pro Mini Launch Date Announced; Colour Options Revealed
  3. Starlink Subscription Price in India Revealed as Elon Musk-Led Firm Prepares for Imminent Launch
  4. Google Releases Gemini 3 Deep Think Model to Its Most Expensive Subscription Tier
  5. Meta’s Phoenix Mixed Reality Smart Glasses Reportedly Delayed; Could Finally Launch in 2027
  6. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  7. OpenAI Clarifies It Isn’t Testing Ads on ChatGPT Despite User Claims
  8. Realme Narzo 90 Series 5G India Launch Announced; to Go on Sale via Amazon
  9. New Shortcut Lets Scientists Run Complex Quantum Models on a Laptop
  10. Glaciers Speed Up in Summer and Slow in Winter, New Global Map Reveals
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.