iOS 16

iOS 16.5 brings new Sports Tab to Apple New and some more bug fixes

iOS 16.5 brings important security fixes

Apple has released iOS 16.5, which will more than likely be the last minor update before the release of iOS 17, which will be unveiled at WWDC on Monday, June 5.

Apple News app now has a Sports tab so that you can easily access information related to your favourite teams and leagues, while My Sports score and schedule cards in the same app will take you to game pages.

There’s a new Pride Celebration wallpaper. This is new. Apple releases a Pride Apple Watch band each year, sometimes two, with several related Watch faces, but an iPhone wallpaper is a change.

iOS 16.5 fixes a Podcasts issue with CarPlay not loading content and sorting out an issue where Spotlight froze. The third fix is about Screen Time and relates to a situation where settings did not reset or sync as they should.

iOS 16.5 Security Fixes

Accessibility

Impact: An app may be able to bypass Privacy preferences

Description: A privacy issue was addressed with improved private data redaction for log entries.

Impact: Entitlements and privacy permissions granted to this app may be used by a malicious app

Description: This issue was addressed with improved checks.

AppleMobileFileIntegrity

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved entitlements.

Associated Domains

Impact: An app may be able to break out of its sandbox

Description: The issue was addressed with improved checks.

Cellular

Impact: A remote attacker may be able to cause arbitrary code execution

Description: The issue was addressed with improved bounds checks.

Core Location

Impact: An app may be able to read sensitive location information

Description: The issue was addressed with improved handling of caches.

CoreServices

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved redaction of sensitive information.

GeoServices

Impact: An app may be able to read sensitive location information

Description: A privacy issue was addressed with improved private data redaction for log entries.

ImageIO

Impact: Processing an image may result in disclosure of process memory

Description: An out-of-bounds read was addressed with improved input validation.

Impact: Processing an image may lead to arbitrary code execution

Description: A buffer overflow was addressed with improved bounds checking.

IOSurfaceAccelerator

Impact: An app may be able to disclose kernel memory

Description: An out-of-bounds read was addressed with improved input validation.

Impact: An app may be able to cause unexpected system termination or read kernel memory

Description: An out-of-bounds read was addressed with improved input validation.

Kernel

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: A type confusion issue was addressed with improved checks.

Impact: An app may be able to execute arbitrary code with kernel privileges

Description: A use-after-free issue was addressed with improved memory management.

Impact: An app may be able to gain root privileges

Description: A race condition was addressed with improved state handling.

LaunchServices

Impact: An app may bypass Gatekeeper checks

Description: A logic issue was addressed with improved checks.

Metal

Impact: An app may be able to bypass Privacy preferences

Description: A logic issue was addressed with improved state management.

Model I/O

Impact: Processing a 3D model may result in disclosure of process memory

Description: An out-of-bounds read was addressed with improved input validation.

NetworkExtension

Impact: An app may be able to read sensitive location information

Description: This  issue was addressed with improved redaction of sensitive information.

PDFKit

Impact: Opening a PDF file may lead to unexpected app termination

Description: A denial-of-service issue was addressed with improved memory handling.

Photos

Impact: Shake-to-undo may allow a deleted photo to be re-surfaced without authentication

Description: The issue was addressed with improved checks.

Impact: Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup

Description: The issue was addressed with improved checks.

Sandbox

Impact: An app may be able to retain access to system configuration files even after its permission is revoked

Description: An authorization issue was addressed with improved state management.

Security

Impact: An app may be able to access user-sensitive data

Description: This issue was addressed with improved entitlements.

Shortcuts

Impact: A shortcut may be able to use sensitive data with certain actions without prompting the user

Description: The issue was addressed with improved checks.

Impact: An app may be able to bypass Privacy preferences

Description: This issue was addressed with improved entitlements.

Siri

Impact: A person with physical access to a device may be able to view contact information from the lock screen

Description: The issue was addressed with improved checks.

SQLite

Impact: An app may be able to access data from other apps by enabling additional SQLite logging

Description: This issue was addressed by adding additional SQLite logging restrictions.

StorageKit

Impact: An app may be able to modify protected parts of the file system

Description: This issue was addressed with improved entitlements.

System Settings

Impact: An app firewall setting may not take effect after exiting the Settings app

Description: This issue was addressed with improved state management.

Telephony

Impact: A remote attacker may be able to cause unexpected app termination or arbitrary code execution

Description: A use-after-free issue was addressed with improved memory management.

TV App

Impact: An app may be able to read sensitive location information

Description: The issue was addressed with improved handling of caches.

Weather

Impact: An app may be able to read sensitive location information

Description: This  issue was addressed with improved redaction of sensitive information.

WebKit

Impact: Processing web content may disclose sensitive information

Description: An out-of-bounds read was addressed with improved input validation.

Impact: Processing web content may disclose sensitive information

Description: A buffer overflow issue was addressed with improved memory handling.

Impact: A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.

Description: The issue was addressed with improved bounds checks.

Impact: Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.

Description: An out-of-bounds read was addressed with improved input validation.

This issue was first addressed in Rapid Security Response iOS 16.4.1 (a) and iPadOS 16.4.1 (a).

Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Description: A use-after-free issue was addressed with improved memory management.

This issue was first addressed in Rapid Security Response iOS 16.4.1 (a) and iPadOS 16.4.1 (a).

Wi-Fi

Impact: An app may be able to disclose kernel memory

Description: This  issue was addressed with improved redaction of sensitive information.

iOS 16.5 Supported Devices

iOS 16.5 will run on all iPhones from iPhone 8 onwards. To be exact:

  • iPhone 14
  • iPhone 14 Plus
  • iPhone 14 Pro
  • iPhone 14 Pro Max
  • iPhone 13
  • iPhone 13 mini
  • iPhone 13 Pro
  • iPhone 13 Pro Max
  • iPhone 12
  • iPhone 12 mini
  • iPhone 12 Pro
  • iPhone 12 Pro Max
  • iPhone 11
  • iPhone 11 Pro
  • iPhone 11 Pro Max
  • iPhone Xs
  • iPhone XS Max
  • iPhone XR
  • iPhone X
  • iPhone 8
  • iPhone 8 Plus
  • iPhone SE (2nd generation or later)

As normal, to update to iOS 16.5, go to your iPhone Settings > General > Software Update and install iOS 16.5 when you can.