Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals. The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both issued in response to the same reported exploitation. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26," reads Apple's security bulletin. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group. CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group. Devices impacted by both flaws include: iPhone 11 and later iPad Pro 12.9-inch (3rd generation and later) iPad Pro 11-inch (1st generation and later) iPad Air (3rd generation and later) iPad (8th generation and later) iPad mini (5th generation and later) Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7.3 and iPadOS 18.7.3, macOS Tahoe 26.2, tvOS 26.2, watchOS 26.2, visionOS 26.2, and Safari 26.2. On Wednesday, Google fixed a mysterious zero-day flaw in Google Chrome, initially labeling it as “[N/A][466192044] High: Under coordination.” However, Google has now updated the advisory to ident...
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
BleepingComputer
·Lawrence Abrams
·Published Dec 12, 2025
·Updated
Affected Software
4 affected components
Apple iOS=26
Apple iPhone=11 and later
Apple iPad Pro=12.9-inch (3rd generation and later)
Apple iPad
Frequently Asked Questions
1
What vulnerabilities were patched in this article?
The article discusses two zero-day vulnerabilities tracked as CVE-2025-43529 and CVE-2025-14174.
2
What platforms are affected by the zero-day vulnerabilities?
The affected platforms include Apple iOS, iPhone models 11 and later, as well as iPad Pro models 12.9-inch (3rd generation and later) and standard iPads.
3
What types of attacks were associated with these vulnerabilities?
The vulnerabilities were exploited in sophisticated attacks specifically targeting certain individuals.
4
How does Apple recommend users respond to these vulnerabilities?
Apple has released emergency updates to patch the vulnerabilities, urging users to update their devices immediately.
5
What does it mean for a vulnerability to be classified as a zero-day?
A zero-day vulnerability refers to a flaw that is exploited by attackers before the vendor becomes aware and releases a fix.