Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Iran’s Infy APT resurfaces with new malware activity after years of silence

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Apple issues security update after two WebKit flaws found to have been exploited
Identity

Apple issues security update after two WebKit flaws found to have been exploited

userBy userDecember 13, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 13, 2025Ravi LakshmananZero-day/vulnerabilities

Apple on Friday released security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and its Safari web browser to address two security flaws that the company announced were being exploited in the wild. One of them is the same flaw that Google patched in Chrome earlier this week.

The vulnerabilities are listed below.

CVE-2025-43529 (CVSS Score: N/A) – Use-after-free vulnerability in WebKit that may lead to arbitrary code execution when processing maliciously crafted web content CVE-2025-14174 (CVSS Score: 8.8) – Memory corruption issue in WebKit that may lead to memory corruption when processing maliciously crafted web content

Apple said it was aware that the flaw “could have been exploited in highly sophisticated attacks against specific targets in versions of iOS prior to iOS 26.”

It’s worth noting that CVE-2025-14174 is the same vulnerability that Google issued a patch for its Chrome browser on December 10, 2025. The vulnerability is described by the tech giant as an out-of-bounds memory access in its open-source Almost Native Graphics Layer Engine (ANGLE) library, specifically the Metal renderer.

Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group (TAG) are credited with discovering and reporting this flaw, and Apple credits TAG with discovering CVE-2025-43529.

cyber security

This indicates that both vulnerabilities are likely to have been weaponized in targeted mercenary spyware attacks, given that both vulnerabilities affect WebKit, the rendering engine also used by all third-party web browsers on iOS and iPadOS, including Chrome, Microsoft Edge, Mozilla Firefox, and more.

This defect has been resolved in the following versions and devices:

iOS 26.2 and iPadOS 26.2 – iPhone 11 or later, iPad Pro 12.9 inch 3rd generation or later, iPad Pro 11 inch 1st generation or later, iPad Air 3rd generation or later, iPad 8th generation or later, iPad mini 5th generation or later iOS 18.7.3 and iPadOS 18.7.3 – iPhone XS or later, iPad Pro 13 inch, iPad Pro 12.9 inch or later 3rd generation or later, iPad Pro 11 inch 1st generation or later, iPad Air 3rd generation or later, iPad 7th generation or later, iPad mini 5th generation or later macOS Tahoe 26.2 – macOS Tahoe tvOS 26.2 – Apple TV HD and Apple TV 4K (all models) watchOS 26.2 – visionOS 26.2 for Apple Watch Series 6 or later – Apple Vision Pro (all models) Safari 26.2 – Macs running macOS Sonoma and macOS Sequoia

With these updates, Apple has identified nine zero-day vulnerabilities that were exploited in the wild in 2025: CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43200, CVE-2025-43300.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleThis week’s science news: Neanderthals start fires, killer whales and dolphins team up, and the Star of Bethlehem is explored
Next Article How is a “traumatic tattoo” made and do you have one?
user
  • Website

Related Posts

Iran’s Infy APT resurfaces with new malware activity after years of silence

December 21, 2025

US Department of Justice charges $54 for ATM jackpotting scheme using Ploutus malware

December 20, 2025

Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Iran’s Infy APT resurfaces with new malware activity after years of silence

Google and Apple reportedly warned employees with visas to avoid traveling abroad

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.