• News/
  • https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/

Apple fixes two zero-day flaws exploited in 'sophisticated' attacks

BleepingComputer
·
Lawrence Abrams
·
Published Dec 12, 2025
·
Updated

Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an “extremely sophisticated attack” targeting specific individuals. The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both issued in response to the same reported exploitation. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26," reads Apple's security bulletin. CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group. CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group. Devices impacted by both flaws include: iPhone 11 and later iPad Pro 12.9-inch (3rd generation and later) iPad Pro 11-inch (1st generation and later) iPad Air (3rd generation and later) iPad (8th generation and later) iPad mini (5th generation and later) Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7.3 and iPadOS 18.7.3, macOS Tahoe 26.2, tvOS 26.2, watchOS 26.2, visionOS 26.2, and Safari 26.2. On Wednesday, Google fixed a mysterious zero-day flaw in Google Chrome, initially labeling it as “[N/A][466192044] High: Under coordination.” However, Google has now updated the advisory to ident...

Read full article

Affected Software

4 affected components
Apple iOS=26
Apple iPhone=11 and later
Apple iPad Pro=12.9-inch (3rd generation and later)
Apple iPad
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities were patched in this article?

The article discusses two zero-day vulnerabilities tracked as CVE-2025-43529 and CVE-2025-14174.

2

What platforms are affected by the zero-day vulnerabilities?

The affected platforms include Apple iOS, iPhone models 11 and later, as well as iPad Pro models 12.9-inch (3rd generation and later) and standard iPads.

3

What types of attacks were associated with these vulnerabilities?

The vulnerabilities were exploited in sophisticated attacks specifically targeting certain individuals.

4

How does Apple recommend users respond to these vulnerabilities?

Apple has released emergency updates to patch the vulnerabilities, urging users to update their devices immediately.

5

What does it mean for a vulnerability to be classified as a zero-day?

A zero-day vulnerability refers to a flaw that is exploited by attackers before the vendor becomes aware and releases a fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203