Apple says it has fixed zero-day flaws used in “sophisticated” attacks


  • Apple Patches Two Zero Day WebKits (CVE‑2025‑43529 and CVE‑2025‑14174) Used in Highly Targeted Attack
  • The flaws were jointly discovered by Google TAG and Apple, with Chrome receiving a parallel patch.
  • The updates cover iOS, iPadOS, macOS, watchOS, tvOS, visionOS, and Safari, with users encouraged to apply patches quickly.

Apple has patched two zero-day vulnerabilities exploited in a “highly sophisticated attack” that, on balance, could have been a cyberespionage attack against one or more high-level individuals.

In a new security advisory, Apple said it has rolled out a fix for a use-after-free remote code execution (RCE) vulnerability in WebKit, as well as a WebKit memory corruption vulnerability.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top