HomeUpdatesApple fixes zero-day affecting many of its devices

Apple fixes zero-day vulnerability affecting many of its devices

Apple has released updates for iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS to address a zero-day vulnerability that has already been used in sophisticated cyberattacks. The vulnerability, tracked as CVE-2026-20700 , has been described as a memory corruption issue in dyld , Apple’s Dynamic Link Editor. Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code with system privileges , which could lead to complete control of the affected device .

Apple fixes zero-day

Apple has not revealed details about exactly how the vulnerability was exploited, but its mention of “sophisticated cyberattacks” suggests that the attacks were targeted and likely part of a broader campaign.

See also: ICS Patch Tuesday: Vulnerabilities fixed by Siemens, Schneider, Aveva, Phoenix Contact

“Apple has seen a report of this issue and its potential exploitation in a highly sophisticated attack against certain individuals running versions of iOS prior to iOS 26,” the company said in an advisory. “CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.”

It is worth noting that both CVE-2025-14174 and CVE-2025-43529 were addressed by the company in December 2025, with the former first disclosed by Google. CVE-2025-14174 (CVSS score: 8.8) is related to “ out-of-bounds memory access ” in the Metal renderer component of ANGLE . Metal is a hardware-accelerated graphics and compute API developed by Apple.

CVE -2025-43529 (CVSS score: 8.8), on the other hand, is a vulnerability in WebKit that can lead to arbitrary code execution when processing malicious web content.

See also: CISA: 6 new Microsoft vulnerabilities in the KEV Catalog

Apple fixes zero-day vulnerability affecting many of its devices

Apple zero-day: Device and OS updates

  • iOS 26.3 and iPadOS 26.3 – iPhone 11 and later, iPad Pro 12.9-inch (3rd generation) and later, iPad Pro 11-inch (1st generation) and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
  • macOS Tahoe 26.3 – Macs running macOS Tahoe
  • tvOS 26.3 – Apple TV HD and Apple TV 4K (all models)
  • watchOS 26.3 – Apple Watch Series 6 and later models
  • visionOS 26.3 – Apple Vision Pro (all models)

Additionally, Apple has released updates to resolve various vulnerabilities in older versions of iOS, iPadOS, macOS, and Safari:

Users of affected devices are urged to immediately update their operating systems to protect themselves from potential attacks.

See also: Anthropic's DXT has a "critical RCE vulnerability"

Apple fixes zero-day vulnerability affecting many of its devices

This vulnerability highlights the importance of regularly updating devices and software to protect against new threats. Apple security updates are available through device settings, and users can easily install them by following the instructions provided.

Apple encourages all users to stay up to date on the latest security updates and urges them to apply them as soon as possible. Protecting personal data and maintaining device security is paramount to the company, and regular updates are a critical part of that effort.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS