The ACSC is tracking a Remote Code Execution vulnerability in Apple WebKit. Apple WebKit is a component used extensively in iOS and macOS devices to display web pages. Apple iOS and macOS products are used widely in Australia, organisations and users should take immediate action and update their devices to prevent compromise.
CVE-2022-22620 allows a malicious actor to execute arbitrary code on an affected device if maliciously crafted web content is processed. Further information on this vulnerability is available in Apple’s security advisories.