Apple says it has fixed zero-day flaws that were used for ‘sophisticated’ attacks


  • Apple patches two WebKit zero-days (CVE-2025-43529 and CVE-2025-14174) used in a highly targeted attack
  • The bug was jointly disclosed by Google TAG and Apple, with Chrome receiving a parallel fix
  • Updates span iOS, iPadOS, macOS, watchOS, tvOS, visionOS and Safari, with users encouraged to patch quickly

Apple patched two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” that, all things considered, could have been a cyber espionage attack against one or a handful of high-profile individuals.

In a new security advisory, Apple said it has deployed a patch for a WebKit remote code execution vulnerability (RCE), as well as a WebKit memory corruption bug.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top