Apple Patches Two Exploited WebKit Zero-Days in Major Update

Apple patches two WebKit zero-day vulnerabilities exploited in the wild, covering iOS, macOS, watchOS, tvOS, visionOS, and Safari in December 2025

  • Apple issued security updates on December 13, 2025, addressing two WebKit vulnerabilities exploited in the wild.
  • One flaw (CVE-2025-14174) is the same as the one patched by Google in Chrome earlier that week.
  • The vulnerabilities risk arbitrary code execution and memory corruption through malicious web content.
  • Updates cover iOS, iPadOS, macOS, watchOS, tvOS, visionOS, and Safari for multiple device models.
  • These fixes mark the ninth set of zero-day vulnerabilities patched by Apple in 2025 exploited in active attacks.

Apple released security patches on December 13, 2025, for its operating systems and Safari browser. These updates address two WebKit security flaws that have been exploited in live attacks, according to the company. One of these vulnerabilities matches a flaw recently fixed by Google in its Chrome browser.

- Advertisement -

The first issue, CVE-2025-43529, is a use-after-free vulnerability in WebKit, which can enable arbitrary code execution when processing malicious web content. The second, CVE-2025-14174, identified with a CVSS score of 8.8, is a memory corruption flaw that may lead to memory corruption under similar conditions. Apple noted that these weaknesses may have been abused in highly sophisticated attacks targeting specific individuals on software versions prior to iOS 26, as mentioned on their support page.

CVE-2025-14174 is associated with an out-of-bounds memory access in the open-source Almost Native Graphics Layer Engine (ANGLE) library, particularly its Metal renderer. This flaw was discovered collaboratively by Apple Security Engineering and Architecture (SEAR) and the Google Threat Analysis Group (TAG), while TAG is credited with reporting CVE-2025-43529, as outlined in related NIST details.

Both vulnerabilities affect WebKit, the core rendering engine used not only by Safari but also by third-party browsers on iOS and iPadOS, including Chrome, Microsoft Edge, and Firefox. This suggests the attacks leveraging these flaws were highly targeted, possibly involving mercenary spyware.

The issues have been resolved in the following versions and devices:

- Advertisement -
  • iOS 26.2 and iPadOS 26.2 for iPhone 11 and newer, various iPad Pro models, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
  • iOS 18.7.3 and iPadOS 18.7.3 covering iPhone XS and newer, iPad Pro models including 13-inch, 12.9-inch 3rd gen and later, 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 7th gen and later, and iPad mini 5th gen and later.
  • macOS Tahoe 26.2 for Macs running that version.
  • tvOS 26.2 for Apple TV HD and Apple TV 4K models.
  • watchOS 26.2 for Apple Watch Series 6 and later.
  • visionOS 26.2 for all Apple Vision Pro models.
  • Safari 26.2 on Macs running macOS Sonoma and macOS Sequoia.

This update brings Apple‘s total count of patched zero-day vulnerabilities exploited in the wild during 2025 to nine. Prior patches addressed issues including CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43200, and CVE-2025-43300.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Waymo Targets 1M Weekly Paid Rides by 2026

Waymo, owned by Alphabet, aims to surpass one million paid rides per week by...

Microsoft: Firms Use AI Buttons to Poison Chatbot Memories

A disturbing new digital manipulation tactic has been uncovered by Microsoft security researchers, who...

Aave Lab Offers Revenue, New Focus to DAO’s End Feud

Aave Labs has proposed a new framework directing all revenue from Aave-branded products to...

Soldier used military secrets for $150K crypto bets.

An Israeli reserve soldier and a civilian accomplice face charges for allegedly using military...

BitGo, 21Shares Expand ETF Staking & Custody Partnership

BitGo and 21Shares have expanded their partnership to provide custody, trading, and staking services...

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!