Iphone ios update fixes xss exploit security issue – Breaking News & Latest Updates 2026
Skip to main content

PSA: I am once again asking you to update your iPhone for security reasons

iOS 14.4.2 fixes security flaws Apple says ‘may have been actively exploited’

iOS 14.4.2 fixes security flaws Apple says ‘may have been actively exploited’

Stock image of an Apple logo against a blue background
Stock image of an Apple logo against a blue background
Illustration by Alex Castro / The Verge

Putting off iOS updates for a week or two is generally fine, but it’s probably a good idea to download the latest one, iOS 14.4.2, as soon as you can. It fixes a security flaw that Apple says may have been exploited out in the wild (via MacRumors). The update also applies to iPadOS, so take a couple of minutes out of your day to go to Settings > General > Software Update.

According to Apple’s update notes, the security flaw allowed for universal cross-site scripting. In other words, a malicious website or script could gain access to information from other webpages you have open, which isn’t great, especially since Apple says that some sites may be doing this.

As I said back in January when Apple released a similar update, this doesn’t mean it’s time to completely lock down your phone and treat it like it’s radioactive until you can get it updated. Just stay clear of sketchy websites (which is good advice in general), and update your phone sooner rather than later.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.