The United States Cybersecurity and Infrastructure Security Agency (CISA) has added three recently disclosed vulnerabilities in Apple operating systems to its Known Exploited Vulnerabilities Catalogue. These vulnerabilities pose a “significant risk to the federal enterprise,” leading to a requirement for US government agencies within the federal civilian executive branch to patch them, following the guidelines of Binding Operational Directive 22-01 issued in November 2021.
CISA strongly advises all organizations to refer to its vulnerabilities catalogue in order to minimize their exposure to cyber attacks. The agency highlights that vulnerabilities like those affecting Apple’s web content rendering engine are frequently targeted by malicious cyber actors.
Last week, Apple released patches that address the identified vulnerabilities. The company stated that undisclosed threat actors were actively exploiting these flaws, but no specific details regarding the actors, locations, or timing were provided.
Two of the vulnerabilities that were actively exploited were patched using Apple’s new Rapid Security Response system, designed to issue urgent updates. The security updates were released for Apple’s Safari web browser, watchOS, tvOS, iOS, iPadOS, and macOS operating systems.
According to the guidelines outlined in BOD 22-01, agencies are required to deploy the patches before or on June 12, based on US time.

