Apple Patches Zero-Day Vulnerabilities Exploited in Sophisticated Attacks
CriticalExecutive Summary
Apple has released patches for actively exploited zero-day vulnerabilities, CVE-2025-43529 and CVE-2025-14174, in targeted attacks. The vulnerabilities impact WebKit and may have been leveraged in a coordinated campaign, requiring immediate patching of affected devices.
Vulnerability Details
- Affected Product: WebKit in Safari, iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. Specifically, iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later). Versions prior to iOS 26 are affected.
- Identifier: CVE-2025-43529, CVE-2025-14174
- CVSS Score: CVE-2025-43529 has a CVSSv3.1 score of 9.8 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Critical. Immediate patching is required to mitigate potential exploitation.
- Attack Vector: Exploitation occurs through processing maliciously crafted web content. CVE-2025-43529 is a use-after-free vulnerability, and CVE-2025-14174 is a memory corruption issue.
- Ease of Exploit: Exploits are sophisticated and targeted, likely used by commercial spyware vendors.
Action Plan
- Immediate Action: Upgrade to iOS 26.2, iPadOS 26.2, iOS 18.7.3, iPadOS 18.7.3, macOS Tahoe 26.2, Safari 26.2, tvOS 26.2, watchOS 26.2, and visionOS 26.2.
- Workaround: There are no known workarounds; patching is the primary mitigation.
- Detection: Monitor for indicators of compromise (IOCs) associated with sophisticated attacks and enhance monitoring for unusual web content processing.
Relevant professional terms
- Zero-day Vulnerability
- A software vulnerability that is known to the software vendor but does not have a patch available, and is actively being exploited by attackers.
- Use-After-Free
- A type of memory corruption vulnerability where memory is incorrectly accessed after it has been freed, potentially leading to arbitrary code execution.
Source: Dark Reading
