Apple releases iOS 15.3.1, iPadOS 15.3.1, and macOS Monterey 12.2.1 to fix a WebKit flaw that may have been actively exploited, its third zero-day patch in 2022
Friday, February 11, 2022 // (IG): BB //Weekly Sponsor: BLKTRIANGLE Mitchell Clark / The Verge : Apple's latest update should fix MacBooks' battery drain issue Tyler Lee / Ubergizmo : iPhone And iPad Owners Need To Update Their Devices ASAP Tweets: Zuk / @ihackbanme : Surprise surprise! Another day another 0day exploited in the wild https://www.bleepingcomputer.com/ ... Incremental patches/mitigations will never work against determined individuals. The only thing that will help to reduce mass surveillance on mobile phones is more eyes. #FreeTheSandbox 👊 Aaron Schaffer / @aaronjschaffer : Apple just released updates to iOS, MacOS, and iPadOS. All fix a vulnerability (CVE-2022-22620) that “may have been actively exploited” #itw0days https://support.apple.com/... https://support.apple.com/... DeWitt Clinton / @dewitt : IMO, if Apple intends to keep having zero-days every few weeks, then iOS/iPadOS releases are going to have to get a heck of a lot lighter and quicker to apply. Updating multiple iPads and an iPhone and a Watch by hand each time is getting to be a drag. https://www.bleepingcomputer.com/ ... Yan / @bcrypt : Apple: free as in use-after https://twitter.com/... Kosta Eleftheriou / @keleftheriou : “Apple is aware of a report that this issue may have been actively exploited,” the company said about a WebKit issue that could lead to [...] code execution on compromised devices. Perhaps a WebKit monoculture isn't such a great idea after all? https://twitter.com/... Tom Warren / @tomwarren : iOS 15.3.1 is out. It patches a 0-day security vulnerability https://www.theverge.com/... https://twitter.com/... Zack Whittaker / @zackwhittaker : Apple just rolled out iOS and iPadOS 15.3.1, and macOS Monterey 12.2.1, to patch a zero-day vulnerability in WebKit that “may have been actively exploited.” Update ASAP. Maddie Stone / @maddiestone : WebKit in-the-wild patched today ⬇️ https://twitter.com/...
Context & Ripple Effects
Apple's update follows a 2021 round of fixes for WebKit and CoreGraphics flaws that had defeated iOS Blastdoor protections. It also precedes the April 2022 patch for two further zero-days, making the release an early marker of a recurring emergency-patch cadence across Apple platforms.
The common WebKit component matters because Apple is issuing coordinated fixes for iOS, iPadOS, and macOS rather than treating the issue as isolated to one device line.
First-order effects
- iPhone, iPad, and Mac users gain patches for a WebKit flaw that Apple says may have been actively exploited, making prompt installation the immediate risk-reduction step.
- Apple must distribute and support parallel updates across its mobile and desktop operating systems, with the flaw becoming its third zero-day patch of 2022.
Second-order effects
- The subsequent two-zero-day update in April increases the operational burden on Apple users and administrators: security maintenance becomes a repeated update cycle rather than a one-off response.
- A shared WebKit flaw concentrates remediation on Apple’s release process across device categories, so delayed updates on any of the three platforms leave a comparable browser-engine exposure unaddressed.
Third-order effects
- The sequence points toward platform security being governed increasingly by the speed and reach of cross-OS emergency patch distribution, as later coverage documents further actively exploited WebKit fixes in 2023.
- If recurring zero-day disclosures persist, Apple’s ecosystem advantage will depend not only on built-in protections such as Blastdoor but on whether users and managed fleets can absorb frequent urgent updates.
The trend: Apple is confronting a sustained pattern of actively exploited browser-engine flaws with coordinated, multi-platform emergency updates.