Apple announced that it has issued emergency updates to fix the two zero-day vulnerabilities in WebKit that have been exploited in "extremely sophisticated" attacks targeting specific individuals, reports BleepingComputer.CVE-2025-43529 is a WebKit use-after-free flaw discovered by Google's Threat Analysis Group that can be triggered via malicious web content, while CVE-2025-14174, identified by both Apple and Google, is a WebKit memory corruption vulnerability. Both flaws affect iPhone 11, and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad mini (5th generation and later), iPad (8th generation and later), and iPad Air (3rd generation and later). Apple has addressed the issues on iOS 18.7.3 and iPadOS 18.7.3, visionOS 26.2, Safari 26.2, OS 26.2 and iPadOS 26.2, tvOS 26.2, watchOS 26.2, and macOS Tahoe 26.2. Google also patched CVE-2025-14174 in Chrome, showing coordinated disclosure.These updates mark Apple's seventh zero-day fix in 2025. Users are strongly urged to install the latest security updates to mitigate the risk of ongoing exploitation.
Vulnerability Management, Patch/Configuration Management
Actively abused zero-day WebKit flaws patched by Apple
(Credit: ink drop – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
