Apple releases iOS 15.3 and macOS Monterey 12.2 with a fix for the IndexedDB API bug in Safari, as well as iPadOS 15.3, watchOS 8.4, tvOS 15.3, and HomePod 15.3
The update follows Apple’s earlier iOS 15.0.1 maintenance release, while related coverage shows the iOS 15 and Monterey line continuing toward later releases. It matters because the Safari issue exposed browser-history and Google-ID information across sites, making a routine OS update a privacy correction.
First-order effects
Users who install iOS 15.3, iPadOS 15.3, or macOS Monterey 12.2 receive Safari’s fix for the IndexedDB flaw that exposed browser-history and Google-ID data to other sites.
Apple completes the rollout of a fix it had previously made available to testers, while also delivering coordinated updates for watchOS, tvOS, and HomePod.
Second-order effects
Sites that could access the leaked IndexedDB-derived information lose that exposure path on updated Apple devices, reducing the privacy risk tied to Safari’s implementation.
Apple’s release process makes OS updates, rather than website-side changes, the mechanism for closing this browser flaw, increasing the importance of prompt adoption across its device base.
Third-order effects
The release reinforces a cross-platform maintenance model in which Apple ships security and reliability fixes through synchronized OS updates; later related coverage of the next iOS 15 and Monterey releases shows that cadence continuing.
As browser privacy defects are addressed through OS releases, platform vendors’ patch speed and users’ update behavior become central parts of web privacy protection.
The trend: Browser privacy is increasingly governed by platform-level patch cycles that span phones, computers, and connected devices.
@danbri Speaking personally, I've been incredibly frustrated with the inability of browser teams to understand that by not flagging things to users, they participate in Apple's abuse of our products and our users. PMs get afraid because Apple might block the update.
It's not like this is the first time! And it surely won't be the last. Apple repeatedly puts users at risk, without recourse, through shoddy practices, underfunding, and enforced web monoculture. Enough's enough.
@slightlylate the question I had for others on this was: precisely what is put at risk here? It isn't login details. It's “what sites I visited”. This seems like something that's a serious problem for a small group, zero for pretty much everyone else. What have I missed?
Hurrah, the iDB data leak bug is fixed in iOS 15.3, a mere 58 days and 18 hours after it was reported to Apple. Thank goodness Apple is so quick off the mark to patch vulnerabilities in the web engine it forces all browsers to use. Under 2 months! Soz if you were hacked. https://…
Bring on iOS 15.4 + macOS 12.3 with IDs in Wallet + Universal Control hopefully! Apple says both features are coming early/spring 2022, which lines up with a March/April release of iOS 15.4 + macOS 12.3. Also likely: code changes related to new products at a Spring Apple Event.
@danbri On the specific question of severity, it's the sort of thing that we'd have dropped other work to fix ASAP and respun stable for, which only happens for super high priority bugs get because the cost of pushes is high.
Apple not including what is new as far as bugs fixes in a point update 15.3 specifically is quite strange. Typically they at least tell us one thing they fixed...
@slightlylate do you have a (personal? company? product team?) view on the seriousness of the risk to users? How bad would it need to be before non-Apple browsers flag things directly to users?
@charlesarthur @thefalken One way to think about this is that it (roughly) undoes what Apple has been banging on about with its removal of third party cookies and state partitioning. And puts Incognito sessions at risk to boot. It's really, really bad.
The questions are legion: - why aren't other, safer engines allowed on iOS? - why is iOS still unable to patch Safari and WebView w/o a full OS update? - why did it take ~2 months from initial report? - why did it take 10 days from public disclosure? https://twitter.com/...
This affects our products, both our browser on iOS and our sites. And we do not have recourse because Apple won't let us keep our iOS users safe. Absolutely infuriating. https://t.co/knZHZNUyzV