logo

Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

ID: 673a91aa-0dbf-5ef0-b505-27c2deec38bb

STIX ID: report--673a91aa-0dbf-5ef0-b505-27c2deec38bb

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-13

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Apple released iOS/iPadOS 26.2 to patch two WebKit zero‑days (CVE-2025-43529 — a use‑after‑free enabling arbitrary code execution, and CVE-2025-14174 — a memory corruption bug) that were actively exploited in targeted spyware campaigns; the update also fixes over 30 other vulnerabilities across Kernel, Screen Time, WebKit, curl and libarchive. Users of iPhone 11 and later and specified iPad models are urged to update immediately to mitigate these nation‑state‑level threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.