HomeSecurityApple fixes Safari vulnerability that is being abused in Chrome

Apple fixes Safari vulnerability that is being exploited in Chrome

Apple on Tuesday announced fixes for dozens of vulnerabilities in its operating systems and a vulnerability in Safari, for mobile devices and computers, including one that has already been exploited in real attacks.

See also: Apple's Safari exposes users to BitM attacks

Safari vulnerability

The vulnerability, identified as CVE-2025-6558, was revealed in mid-July when Google addressed it in Chrome, attributing the report to its Threat Analysis Group and warning that it had already been targeted as a zero-day.

The vulnerability concerns insufficient checking of untrusted inputs to Chrome's ANGLE and GPU graphics components. It can be exploited remotely via malicious HTML, allowing an escape from the browser sandbox.

A week after Google's Chrome 138 update , the U.S. Cybersecurity Intelligence Agency (CISA) added the vulnerability to its "Known Exploited Vulnerabilities" (KEV) list, urging federal agencies to address it by August 12. So far, there have been no public reports of attacks exploiting the CVE-2025-6558 vulnerability.

Apple's recent security updates for iOS and macOS include a fix for CVE-2025-6558, which affects WebKit and could cause Safari to crash when visiting malicious pages. There is no evidence that the vulnerability has been exploited against Safari users.

See also: Apple fixes serious security flaws in iOS and macOS

Apple fixes Safari vulnerability that is being exploited in Chrome
Apple fixes Safari vulnerability that is being exploited in Chrome

In total, the Cupertino-based company released patches for 13 security vulnerabilities in WebKit, warning that they could be exploited for XSS attacks, leaking sensitive user information, corrupting memory, crashing Safari, or causing a denial of service (DoS) condition. While WebKit garnered the largest number of fixes, other individual components of Apple's platforms also received updates, including AppleMobileFileIntegrity, Model I/O , and PackageKit.

According to Jamf VP Josh Stein, another major vulnerability that was recently patched is CVE-2025-43223. This one affects the CFNetwork component on both macOS and iOS, and allows unprivileged users to modify limited network settings.

With the recent macOS Sequoia 15.6, Apple fixed a total of 87 CVEs, while the new iOS 18.6 and iPadOS 18.6 releases include fixes for 29 security bugs.

See also: Apple patches third zero-day vulnerability this year

Users are advised to update their mobile, desktop, and wearable devices as soon as possible. Additional information about the vulnerabilities that have been resolved can be found on Apple's security releases page

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS