Apple issues patch for desktop Safari browser and OS X to fix zero-day vulnerabilities, which are similar to those used in NSO's iOS attack discovered last week
Apple has released Important Security Updates Sean Michael Kerner / eWeek : Apple Patches OS X a Week After Fixing iOS Zero-Days Brian Feldman / New York Magazine : Apple Just Patched a Serious Vulnerability, So You Should Update Your Mac Don Reisinger / Fortune : That Really Scary iOS Security Flaw Also Affects Your Mac Dave Neal / Inquirer : Apple issues emergency security patches for El Capitan and Yosemite Aman Jain / ValueWalk : Apple Inc. Fixes OS X For Security Flaw That First Marred iOS Thanks: @derektmead
Context & Ripple Effects
Last week's discovery of NSO's iOS attack forced an emergency iPhone patch; this update extends the response to the desktop, fixing zero-days in Safari and OS X that resemble the ones used against iOS, across both El Capitan and Yosemite.
It matters because the browser engine is the shared surface: the same WebKit code that exposed iPhones reappears on the Mac, a pattern that recurs years later when Apple ships a WebKit zero-day fix for iOS 15.3.1 and Monterey 12.2.1 and again with the Ventura 13.2.1 actively-exploited WebKit patch.
First-order effects
- Mac users on El Capitan and Yosemite running Safari are the immediate exposure, and the patch closes the desktop leg of an exploit chain already demonstrated against iOS via NSO's attack.
Second-order effects
- Spyware vendors like NSO lose a working desktop entry point, pushing the market for such exploits toward fresh WebKit bugs rather than reused ones.
Third-order effects
- Because one browser engine spans iPhone and Mac, a single bug class forces Apple into a standing emergency-patch cadence across every OS at once — by 2023 the company was fixing sixteen zero-days in a single year under exactly this pattern.
The trend: Shared WebKit code keeps turning single spyware discoveries into platform-wide emergency patch cycles for Apple.