Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw

Posted on December 15, 2025December 15, 2025 By CWS

Apple has launched macOS and iOS updates to patch dozens of vulnerabilities, together with two zero-days that the tech large says have been exploited in extremely focused assaults.

In response to Apple’s advisories, the zero-days influence WebKit, the browser engine current in Safari, iOS, iPadOS, macOS, tvOS, watchOS, and visionOS.

One of many zero-days, CVE-2025-14174, has been described as a reminiscence corruption challenge, whereas the second, CVE-2025-43529, is a use-after-free bug. They will each be exploited utilizing maliciously crafted internet content material to execute arbitrary code. 

Apple introduced patches for CVE-2025-14174 and CVE-2025-43529 with the discharge of iOS and iPadOS 26.2, iOS and iPadOS 18.7.3, macOS Tahoe 26.2, Safari 26.2 for macOS, tvOS 26.2, watchOS 26.2, and visionOS 26.2.

Nonetheless, Apple’s advisories make clear that the vulnerabilities have been exploited in “a particularly subtle assault in opposition to particular focused people on variations of iOS earlier than iOS 26”.

The tech large stated the vulnerabilities have been found by its personal safety group and Google’s Menace Evaluation Group.

This, together with the temporary description of the assaults, signifies that the zero-days have seemingly been exploited by industrial adware distributors, that are recognized to focus on Android, iOS, macOS, Chrome, and WhatsApp.

CVE-2025-14174 is the mysterious Chrome zero-day

Google final week introduced patches for a mysterious Chrome zero-day. The corporate stated it had seen an exploit within the wild, however the flaw initially didn’t have a CVE identifier or any description, apart from a ‘excessive severity’ ranking.Commercial. Scroll to proceed studying.

Google has now up to date its authentic advisory to make clear that the beforehand unidentified zero-day is CVE-2025-14174. 

The corporate says the safety gap is an out-of-bounds reminiscence entry challenge within the Angle graphics library. As a result of Angle is utilized by each Chrome’s Blink browser engine and WebKit, the zero-day impacts each Google and Apple merchandise.

It seems Google and Apple have been coordinating the disclosure and patching of the vulnerability. In response to Google’s advisory, the problem got here to gentle on December 5.

Google has not shared any data on assaults focusing on Chrome customers.

It’s additionally value noting that the Angle library is utilized by Chromium, and different Chromium-based browsers corresponding to Edge, Opera, Vivaldi, and Courageous are impacted as properly. 

Microsoft has already up to date Edge to deal with CVE-2025-14174. Vivaldi has additionally been up to date to patch the zero-day. 

CISA has added CVE-2025-14174 to its Recognized Exploited Vulnerabilities (KEV) catalog. 

Associated: Apple Patches Zero-Day Exploited in Focused Assaults

Associated: CISA Warns of Spyware and adware Concentrating on Messaging App Customers

Associated: Landfall Android Spyware and adware Focused Samsung Telephones by way of Zero-Day

Security Week News Tags:Apple, Chrome, Exploited, Flaw, Mysterious, Patches, Tied, ZeroDays

Post navigation

Previous Post: Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution
Next Post: 700Credit Data Breach Impacts 5.8 Million Individuals

Related Posts

SonicWall Hunts for Zero-Day Amid Surge in Firewall Exploitation Security Week News
AI Is Supercharging Phishing: Here’s How to Fight Back Security Week News
Ongoing Campaign Uses 60 NPM Packages to Steal Data Security Week News
NASCAR Confirms Personal Information Stolen in Ransomware Attack Security Week News
From 60 to 4,000: NATO’s Locked Shields Reflects Cyber Defense Growth Security Week News
Virtual Event Today: Zero Trust & Identity Strategies Summit Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More
  • Soverli Raises $2.6 Million for Secure Smartphone OS
  • New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code
  • Atlassian Patches Critical Apache Tika Flaw
  • AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple 0-Days, WinRAR Exploit, LastPass Fines, .NET RCE, OAuth Scams & More
  • Soverli Raises $2.6 Million for Secure Smartphone OS
  • New Clickfix Attack Exploits finger.exe Tool to Trick Users into Execute Malicious Code
  • Atlassian Patches Critical Apache Tika Flaw
  • AI Pentesting Tool that Autonomously Checks for Code Vulnerabilities and Executes Real Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark