Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

Posted on December 13, 2025December 13, 2025 By CWS

Apple patches two WebKit zero-day flaws actively exploited in refined assaults concentrating on particular iPhone customers operating iOS variations previous to 26.​

The iOS 26.2 and iPadOS 26.2 updates, launched December 12, 2025, handle CVE-2025-43529 and CVE-2025-14174 in WebKit. CVE-2025-43529 includes a use-after-free vulnerability enabling arbitrary code execution through malicious net content material, found by Google Menace Evaluation Group.

CVE-2025-14174 is a associated reminiscence corruption subject, credited to Apple and Google TAG, with each flaws linked to focused spyware and adware campaigns.​

CVE IDComponentImpactDescriptionResearcher(s)CVE-2025-43529WebKitArbitrary code executionUse-after-free, improved reminiscence managementGoogle Menace Evaluation Group ​CVE-2025-14174WebKitMemory corruptionImproved validationApple & Google TAG ​

These flaws have an effect on iPhone 11 and later fashions, plus specified iPad Professional, Air, and mini variants.​

Different Essential Fixes

Apple resolved over 30 vulnerabilities throughout elements like Kernel, Basis, Display Time, and curl. Notable points embrace a Kernel integer overflow (CVE-2025-46285) permitting root privilege escalation, found by Alibaba Group researchers, and a number of Display Time logging flaws exposing Safari historical past or consumer information (CVE-2025-46277, CVE-2025-43538).

WebKit noticed further patches for sort confusion, buffer overflows, and crashes (e.g., CVE-2025-43541, CVE-2025-43501). Open-source flaws in libarchive (CVE-2025-5918) and curl (CVE-2024-7264, CVE-2025-9086) had been additionally addressed.​

ComponentCVE IDImpactKey ResearcherKernelCVE-2025-46285Root privilegesKaitao Xie, Xiaolong Bai ​Display TimeCVE-2025-46277Access Safari historyKirin (@Pwnrin)​MessagesCVE-2025-46276Access delicate dataRosyna Keller​

Affected Units and Mitigation

Impacts span iPhone 11+, iPad Professional 12.9-inch (third gen+), iPad Professional 11-inch (1st gen+), iPad Air (third gen+), iPad (eighth gen+), and iPad mini (fifth gen+).

Customers ought to replace instantly through Settings > Basic > Software program Replace to mitigate dangers from these focused exploits, per patterns seen in prior spyware and adware assaults. Apple notes no particulars on attackers, however collaboration with Google underscores nation-state-level threats.​

ProductAffected VersionsPatched VersionCompatible DevicesiOSBefore 26.2 (exploited pre-26)26.2iPhone 11 and later​iPadOSBefore 26.2 (exploited pre-26)26.2iPad Professional 12.9″ (third gen+), iPad Professional 11″ (1st gen+), iPad Air (third gen+), iPad (eighth gen+), iPad mini (fifth gen+)​

Observe us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:0Day, Apple, Attacks, Exploited, iPhone, Sophisticated, Targeting, Users, Vulnerabilities

Post navigation

Previous Post: Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads
Next Post: Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild

Related Posts

Shanya EDR Killer Leveraged by Hackers to Clear the Way for Ransomware Infection Shanya EDR Killer Leveraged by Hackers to Clear the Way for Ransomware Infection Cyber Security News
ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing Cyber Security News
DragonForce Cartel Emerges From the Leaked Source Code of Conti v3 Ransomware DragonForce Cartel Emerges From the Leaked Source Code of Conti v3 Ransomware Cyber Security News
Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Beware of New back-to-school Shopping Scams That Tricks Drives Users to Fake Shopping Sites Cyber Security News
EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections EvilAI as AI-enhanced Tools to Exfiltrate Sensitive Browser Data and Evade Detections Cyber Security News
Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark