Apple has released emergency security updates to fix a zero-day vulnerability that has already been used in "highly sophisticated" attacks.

The vulnerability is tracked as CVE-2025-24201 and was detected in WebKit, which is used by Apple's Safari and many other applications and browsers.
“This is a supplemental fix for an attack that was blocked in iOS 17.2,” the company said. “Apple is aware that this issue may have been exploited in a highly sophisticated attack against specific individuals running versions of iOS prior to iOS 17.2.”
See also: Edimax Camera Zero-Day Exploited by Botnets
Apple said that attackers can exploit the zero-day vulnerability by using maliciously crafted web content to escape the Web Content sandbox.
The company has fixed this issue with improved checks to prevent unauthorized actions: iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2 , and Safari 18.3.1.
The zero-day vulnerability affects older and newer Apple device models:
- iPhone XS and later models
- iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
- Macs running macOS Sequoia
- Apple Vision Pro
Apple has not released details about the "highly sophisticated" attacks that exploit the zero-day vulnerability CVE-2025-24201.
See also: BigAnt server zero-day vulnerability allows malicious code execution
Although the bug was likely only used in targeted attacks, installing security updates immediately is very important.
This is the third zero-day vulnerability that Apple has patched since the beginning of the year. The first was patched in January (CVE-2025-24085) and the second in February (CVE-2025-24200).

What are the latest techniques for dealing with Zero-Day vulnerabilities?
One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.
See also: Zero-Day Windows driver vulnerability allows remote access
Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.
Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.
Source: www.bleepingcomputer.com
