iOS 15

iOS 15.6 brings a bunch of security and bug fixes

iOS 15.6 brings 36 security fixes, including flaws that allow malicious apps to execute arbitrary code with kernel privileges

Apple has released iOS 15.6, bringing  bug fixes, security updates, and small enhancements to the operating system.

Most notable is a resolution to an issue where the Settings app may erroneously state that the storage is full, despite having storage available.

Additionally, there are new options to pause, rewind, and restart live sports games in the TV app, and bug fixes for braille devices when using Mail, and a fix for a Safari problem where tabs may revert back to previous pages.

iOS 15.6 Security Fixes

iOS 15.6 also brings 36 security fixes, including flaws that allow malicious apps to execute arbitrary code with kernel privileges.

APFS

Impact: An app with root privileges may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

AppleAVD

Impact: A remote user may be able to cause kernel code execution

Description: A buffer overflow was addressed with improved bounds checking.

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

AppleMobileFileIntegrity

Impact: An app may be able to gain root privileges

Description: An authorization issue was addressed with improved state management.

Apple Neural Engine

Impact: An app may be able to break out of its sandbox

Description: This issue was addressed with improved checks.

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: This issue was addressed with improved checks.

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

Audio

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: An out-of-bounds write issue was addressed with improved input validation.

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

CoreMedia

Impact: An app may be able to disclose kernel memory

Description: The issue was addressed with improved memory handling.

CoreText

Impact: A remote user may cause an unexpected app termination or arbitrary code execution

Description: The issue was addressed with improved bounds checks.

File System Events

Impact: An app may be able to gain root privileges

Description: A logic issue was addressed with improved state management.

GPU Drivers

Impact: An app may be able to disclose kernel memory

Description: Multiple out-of-bounds write issues were addressed with improved bounds checking.

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: A memory corruption issue was addressed with improved validation.

Home

Impact: A user may be able to view restricted content from the lock screen

Description: A logic issue was addressed with improved state management.

iCloud Photo Library

Impact: An app may be able to access sensitive user information

Description: An information disclosure issue was addressed by removing the vulnerable code.

ICU

Impact: Processing maliciously crafted web content may lead to arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved bounds checking.

ImageIO

Impact: Processing a maliciously crafted image may result in disclosure of process memory

Description: The issue was addressed with improved memory handling.

Impact: Processing a maliciously crafted file may lead to arbitrary code execution

Description: A logic issue was addressed with improved checks.

Impact: Processing a maliciously crafted image may lead to disclosure of user information

Description: An out-of-bounds read issue was addressed with improved bounds checking.

Impact: Processing an image may lead to a denial-of-service

Description: A null pointer dereference was addressed with improved validation.

IOMobileFrameBuffer

Impact: An application may be able to execute arbitrary code with kernel privileges

Description: A memory corruption issue was addressed with improved state management.

Kernel

Impact: An app with root privileges may be able to execute arbitrary code with kernel privileges

Description: The issue was addressed with improved memory handling.

Impact: An app may be able to disclose kernel memory

Description: An out-of-bounds read issue was addressed with improved bounds checking.

Impact: An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication

Description: A logic issue was addressed with improved state management.

Impact: An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication

Description: A race condition was addressed with improved state handling.

Liblouis

Impact: An app may cause unexpected app termination or arbitrary code execution

Description: This issue was addressed with improved checks.

libxml2

Impact: An app may be able to leak sensitive user information

Description: A memory initialization issue was addressed with improved memory handling.

Multi-Touch

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: A type confusion issue was addressed with improved state handling.

PluginKit

Impact: An app may be able to read arbitrary files

Description: A logic issue was addressed with improved state management.

Safari Extensions

Impact: Visiting a maliciously crafted website may leak sensitive data

Description: The issue was addressed with improved UI handling.

Software Update

Impact: A user in a privileged network position can track a user’s activity

Description: This issue was addressed by using HTTPS when sending information over the network.

WebKit

Impact: Visiting a website that frames malicious content may lead to UI spoofing

Description: The issue was addressed with improved UI handling.

Impact: Processing maliciously crafted web content may lead to arbitrary code execution

Description: An out-of-bounds write issue was addressed with improved input validation.

WebRTC

Impact: Processing maliciously crafted web content may lead to arbitrary code execution

Description: A memory corruption issue was addressed with improved state management.

Wi-Fi

Impact: An app may be able to cause unexpected system termination or write kernel memory

Description: This issue was addressed with improved checks.

Impact: A remote user may be able to cause unexpected system termination or corrupt kernel memory

Description: This issue was addressed with improved checks.

iOS 15.6 Availability

iOS 15.6 is available for iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation)

You can download the update by opening the Settings app and going to General > Software Update.