Apple on Tuesday announced fixes for dozens of vulnerabilities in its operating systems and a vulnerability in Safari, for mobile devices and computers, including one that has already been exploited in real attacks.
See also: Apple's Safari exposes users to BitM attacks

The vulnerability, identified as CVE-2025-6558, was revealed in mid-July when Google addressed it in Chrome, attributing the report to its Threat Analysis Group and warning that it had already been targeted as a zero-day.
The vulnerability concerns insufficient checking of untrusted inputs to Chrome's ANGLE and GPU graphics components. It can be exploited remotely via malicious HTML, allowing an escape from the browser sandbox.
A week after Google's Chrome 138 update , the U.S. Cybersecurity Intelligence Agency (CISA) added the vulnerability to its "Known Exploited Vulnerabilities" (KEV) list, urging federal agencies to address it by August 12. So far, there have been no public reports of attacks exploiting the CVE-2025-6558 vulnerability.
Apple's recent security updates for iOS and macOS include a fix for CVE-2025-6558, which affects WebKit and could cause Safari to crash when visiting malicious pages. There is no evidence that the vulnerability has been exploited against Safari users.
See also: Apple fixes serious security flaws in iOS and macOS

In total, the Cupertino-based company released patches for 13 security vulnerabilities in WebKit, warning that they could be exploited for XSS attacks, leaking sensitive user information, corrupting memory, crashing Safari, or causing a denial of service (DoS) condition. While WebKit garnered the largest number of fixes, other individual components of Apple's platforms also received updates, including AppleMobileFileIntegrity, Model I/O , and PackageKit.
According to Jamf VP Josh Stein, another major vulnerability that was recently patched is CVE-2025-43223. This one affects the CFNetwork component on both macOS and iOS, and allows unprivileged users to modify limited network settings.
With the recent macOS Sequoia 15.6, Apple fixed a total of 87 CVEs, while the new iOS 18.6 and iPadOS 18.6 releases include fixes for 29 security bugs.
See also: Apple patches third zero-day vulnerability this year
Users are advised to update their mobile, desktop, and wearable devices as soon as possible. Additional information about the vulnerabilities that have been resolved can be found on Apple's security releases page
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
