{"id":9177,"date":"2025-12-13T10:03:39","date_gmt":"2025-12-13T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/13\/apple-0-day-vulnerabilities-exploited-in-sophisticated-attacks-targeting-iphone-users\/"},"modified":"2025-12-13T10:03:39","modified_gmt":"2025-12-13T10:03:39","slug":"apple-0-day-vulnerabilities-exploited-in-sophisticated-attacks-targeting-iphone-users","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/13\/apple-0-day-vulnerabilities-exploited-in-sophisticated-attacks-targeting-iphone-users\/","title":{"rendered":"Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users"},"content":{"rendered":"<p>    Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Apple patches two WebKit zero-day flaws actively exploited in sophisticated attacks targeting specific iPhone users running iOS versions prior to 26.\u200b<\/p>\n<p>The iOS 26.2 and iPadOS 26.2 updates, released December 12, 2025, address CVE-2025-43529 and CVE-2025-14174 in WebKit. CVE-2025-43529 involves a <a href=\"https:\/\/cybersecuritynews.com\/use-after-free-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">use-after-free vulnerability<\/a> enabling arbitrary code execution via malicious web content, discovered by Google Threat Analysis Group.<\/p>\n<p>CVE-2025-14174 is a related memory corruption issue, credited to Apple and Google TAG, with both flaws linked to targeted spyware campaigns.\u200b<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Component<\/th>\n<th>Impact<\/th>\n<th>Description<\/th>\n<th>Researcher(s)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-43529<\/td>\n<td>WebKit<\/td>\n<td>Arbitrary code execution<\/td>\n<td>Use-after-free, improved memory management<\/td>\n<td>Google Threat Analysis Group \u200b<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-14174<\/td>\n<td>WebKit<\/td>\n<td>Memory corruption<\/td>\n<td>Improved validation<\/td>\n<td>Apple &amp; Google TAG \u200b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>These flaws affect iPhone 11 and later models, plus specified iPad Pro, Air, and mini variants.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"other-critical-fixes\"><strong>Other Critical Fixes<\/strong><\/h2>\n<p>Apple <a href=\"https:\/\/support.apple.com\/en-us\/125884\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">resolved<\/a> over 30 vulnerabilities across components like Kernel, Foundation, Screen Time, and curl. Notable issues include a Kernel integer overflow (CVE-2025-46285) allowing root privilege escalation, discovered by Alibaba Group researchers, and multiple Screen Time logging flaws exposing Safari history or user data (CVE-2025-46277, CVE-2025-43538).<\/p>\n<p>WebKit saw additional patches for type confusion, <a href=\"https:\/\/cybersecuritynews.com\/what-is-buffer-overflow\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflows<\/a>, and crashes (e.g., CVE-2025-43541, CVE-2025-43501). Open-source flaws in libarchive (CVE-2025-5918) and curl (CVE-2024-7264, CVE-2025-9086) were also addressed.\u200b<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Component<\/th>\n<th>CVE ID<\/th>\n<th>Impact<\/th>\n<th>Key Researcher<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Kernel<\/td>\n<td>CVE-2025-46285<\/td>\n<td>Root privileges<\/td>\n<td>Kaitao Xie, Xiaolong Bai \u200b<\/td>\n<\/tr>\n<tr>\n<td>Screen Time<\/td>\n<td>CVE-2025-46277<\/td>\n<td>Access Safari history<\/td>\n<td>Kirin (@Pwnrin)\u200b<\/td>\n<\/tr>\n<tr>\n<td>Messages<\/td>\n<td>CVE-2025-46276<\/td>\n<td>Access sensitive data<\/td>\n<td>Rosyna Keller\u200b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"affected-devices-and-mitigation\"><strong>Affected Devices and Mitigation<\/strong><\/h2>\n<p>Impacts span iPhone 11+, iPad Pro 12.9-inch (3rd gen+), iPad Pro 11-inch (1st gen+), iPad Air (3rd gen+), iPad (8th gen+), and iPad mini (5th gen+). <\/p>\n<p>Users should update immediately via Settings &gt; General &gt; Software Update to mitigate risks from these targeted exploits, consistent with patterns seen in prior spyware attacks. Apple notes no details on attackers, but collaboration with Google underscores nation-state-level threats.\u200b<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Product<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Affected Versions<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Patched Version<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Compatible Devices<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">iOS<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before 26.2 (exploited pre-26)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">26.2<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iPhone 11 and later\u200b<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">iPadOS<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Before 26.2 (exploited pre-26)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">26.2<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">iPad Pro 12.9\u2033 (3rd gen+), iPad Pro 11\u2033 (1st gen+), iPad Air (3rd gen+), iPad (8th gen+), iPad mini (5th gen+)\u200b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apple-0-day-vulnerabilities-exploited-2\/\">Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apple-0-day-vulnerabilities-exploited-2\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users Apple patches two WebKit zero-day flaws actively exploited in sophisticated attacks targeting specific iPhone users running iOS versions prior to 26.\u200b The iOS 26.2 and iPadOS 26.2 updates, released December 12, 2025, address CVE-2025-43529 and CVE-2025-14174 in WebKit. CVE-2025-43529 involves a use-after-free vulnerability enabling arbitrary [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-9177","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9177"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9177"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9177\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9177"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9177"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9177"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}