HomeUpdatesApple fixes two zero-day WebKit vulnerabilities

Apple patches two zero-day WebKit vulnerabilities

Apple on Friday released security updates for iOS, iPadOS, macOS , tvOS, watchOS, visionOS and the Safari browser to address two security vulnerabilities that have been exploited by hackers. One of those vulnerabilities is the same one that Google patched in Chrome last week.

Apple WebKit
  • CVE -2025-43529 is a 'use-after-free' vulnerability in WebKit that could lead to arbitrary code execution when processing malicious web content.
  • CVE -2025-14174 is also a problem in WebKit that can lead to memory corruption when processing malicious web content.

Apple said these vulnerabilities “may have been exploited in a highly sophisticated attack against specific individuals, in versions of iOS prior to iOS 26.”

See also: Notepad++ fixes serious security vulnerability

CVE-2025-14174: A vulnerability affecting Apple and Google

CVE-2025-14174 is the same vulnerability for which Google issued fixes in the Chrome browser on December 10, 2025. It is described by Google as an “ out-of-bounds memory access ” in the company’s Almost Native Graphics Layer Engine (ANGLE) library (specifically in its Metal renderer ).

Apple Security Engineering and Architecture (SEAR) and Google Threat Analysis Group (TAG) are behind the discovery and reporting of the vulnerability, with Apple crediting TAG for finding CVE-2025-43529. These vulnerabilities were likely used in attacks spyware, as they affect WebKit, the rendering engine used in all third-party browsers on iOS and iPadOS, including Chrome, Microsoft Edge, Mozilla Firefox, and others.

See also: Adobe Acrobat Reader: Critical Vulnerabilities Patched

Apple patches two zero-day WebKit vulnerabilities

The vulnerabilities have been addressed in the following versions and devices:

– iOS 26.2 and iPadOS 26.2: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

– iOS 18.7.3 and iPadOS 18.7.3: iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.

– macOS Tahoe 26.2: Macs running macOS Tahoe.

– tvOS 26.2: Apple TV HD and Apple TV 4K (all models).

– watchOS 26.2: Apple Watch Series 6 and later.

– visionOS 26.2: Apple Vision Pro (all models).

– Safari 26.2: Macs running macOS Sonoma and macOS Sequoia.

See also: GitLab fixed 10 security vulnerabilities

Apple patches two zero-day WebKit vulnerabilities

With these updates, Apple has now fixed nine zero-day vulnerabilities in 2025, including CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43200, and CVE-2025-43300.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS