On December 12, 2025, Apple released a set of crucial security updates for its various operating systems, aiming to correct two critical flaws in the WebKit browsing engine. Essas vulnerabilities, cataloged as CVE-2025-43529 and CVE-2025-14174, presented the risk of arbitrary code execution or memory corruption, and could be activated simply when processing malicious web content. The company’s quick response demonstrates the seriousness with which it treats threats that could compromise the integrity of data and the privacy of its users, especially in an increasingly complex and challenging cybersecurity scenario for the technology sector.
The company confirmed that both flaws have already been exploited in highly targeted attacks. Esses attacks targeted specific individuals, using older versions of iOS to compromise device security. The CVE-2025-14174 vulnerability, in particular, also affected the Chrome browser of Google, which received a separate fix on December 10, 2025, highlighting the collaboration between the technology giants in mitigating risks.
The updates cover a wide range of platforms, including iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari. Para ensure the protection of their equipment, users must install the latest versions of software as quickly as possible, in order to mitigate the risks of exploitation and maintain the integrity of their systems against digital threats.
Nature of security flaws in WebKit
CVE-2025-43529 was identified as a use-after-free issue within WebKit, a fundamental component for rendering web pages. Essa flaw allowed attackers to insert and execute malicious code on compromised devices, simply by having victims access web pages that had been prepared with exploitable content.
Researchers from Google Threat Analysis Group (TAG) were responsible for identifying and reporting the issue to Apple, highlighting the importance of continuous surveillance and collaboration between security companies. Exploitation of this vulnerability was particularly insidious because it required only one passive action from the victim: browsing a compromised website, without the need for additional downloads or installations.
The second flaw, CVE-2025-14174, involved serious memory corruption during web content processing, with a CVSS score of 8.8. Esta rating indicates high severity and significant potential to cause damage to affected systems.
Both vulnerabilities directly impact WebKit, which is the mandatory rendering engine for all browsers on iOS and iPadOS. Essa dependency means that any flaw in WebKit could compromise the security of all browsing applications on these systems.
Impact and coordination with Google
The nature of these flaws, which allow remote code execution without additional user interaction, is particularly concerning. Elas open doors for installing spy software and other surveillance tools on target devices.
Although exploits have been limited to targeted campaigns rather than mass attacks, the risk to targeted individuals is substantial. The coordination between Apple and Google in fixing CVE-2025-14174, which also affected the ANGLE library in Chrome, demonstrates a unified approach to addressing threats that transcend a single software ecosystem.
Devices and systems that have received updates
The fixes were distributed in platform-specific versions, ensuring that Apple’s wide range of devices were protected. Para users of iPhones and iPads, the updates arrived through iOS 26.2 and iPadOS 26.2, while older models were covered with iOS 18.7.3 and iPadOS 18.7.3, ensuring compatibility and security for a larger fleet of equipment.
Learn more: Users avoid iOS 26 by AI and Liquid Glass and leave iPhone vulnerable to hackers
These updates cover iPhones from model XS onwards, several recent generations of iPads, and all compatible iPad mini models, ensuring that a broad user base receives the necessary protections. In the macOS environment, the update was implemented in macOS Tahoe 26.2, applying to all Macs that run this version of the operating system, strengthening security on desktops and notebooks.
– tvOS 26.2: Disponível for Apple HD TV and all 4K models.
– watchOS 26.2: Abrangendo Apple Watch Series 6 and later models.
– visionOS 26.2: Para all models of Apple Vision Pro.
– Safari 26.2: Macs with macOS Sonoma or Sequoia also received the updated browser.
[[_0]
Users can receive updates automatically or can choose to install them manually by accessing the software settings of their respective devices, a simple and straightforward process that guarantees protection in just a few minutes.
History of zero-day vulnerabilities in 2025
With these latest fixes, Apple has already addressed nine zero-day vulnerabilities actively exploited throughout 2025, a number that highlights the persistence and sophistication of attackers. At the beginning of the year, the company had already released patches for critical flaws such as CVE-2025-24085, CVE-2025-24200 and CVE-2025-24201, demonstrating a continuous effort to keep its systems secure.
Other vulnerabilities identified and fixed included CVE-2025-31200, CVE-2025-31201, CVE-2025-43200, and CVE-2025-43300. Muitas of these flaws involved essential system components, such as Kernel and ImageIO, which are frequently targeted due to their privileged access to device resources.
The frequency with which zero-day vulnerabilities are discovered and exploited reflects the growing interest of advanced attacker groups in the Apple ecosystems, driven by the popularity and value of the data stored on these devices. Collaboration with entities like the Google TAG has been critical to the rapid detection and effective mitigation of these threats, allowing companies to act proactively.
These incidents serve as a constant reminder of the critical importance of keeping operating systems and applications up to date. Regularly installing security patches on mobile devices and desktops is the main line of defense against attacks that seek to exploit newly discovered flaws before fixes are widely available.
WebKit’s essential role in the Apple ecosystem
WebKit, an open source rendering engine, is the heart of the Safari browser and, by extension, all browsers operating on iOS and iPadOS. Devido Due to the strict security restrictions imposed by Apple, all third-party browsers, including Chrome, Edge, and Firefox, are required to use WebKit on iOS and iPadOS devices.
This centralized dependency makes any vulnerability in WebKit particularly critical for Apple’s vast user base. A flaw in this engine can be exploited through any alternative browser without the need to install additional malicious applications, making the attack vector very broad and easily accessible for cyber criminals.
The ANGLE library, which was involved in CVE-2025-14174, is responsible for managing WebGL graphics, a technology that enables browser-based 3D graphics rendering. Problemas in this layer can have a widespread impact, affecting the rendering of visual content across multiple platforms and compromising the user experience.
Full coverage: News (EN)
Fortunately, the improvements implemented in memory management and data validation within WebKit are specifically designed to address the reported crashes. Essas optimizations aim to strengthen the engine’s resilience against future exploitation attempts, ensuring safer browsing for everyone.
Additional protective measures and other corrections
Recent Apple updates have not only been limited to WebKit flaws, but have also included patches for more than 20 additional vulnerabilities in various system components. Problemas in Kernel, like integer overflows, could, for example, allow privilege escalation, giving an attacker full control over the device.
Flaws in important frameworks such as FaceTime, Messages and App Store also received the necessary corrections. Algumas of these vulnerabilities involved improper access to sensitive user data, such as contact information or communication history, which could lead to serious privacy violations.
– CVE-2025-46285: An overflow in Kernel with the potential to grant root access.
– Problemas on Screen Time that exposed users’ browsing history.
– Correções in network modules like curl, strengthening communications security.
These comprehensive improvements strengthen the overall security of Apple’s operating systems, mitigating a variety of threats that could be exploited in future attacks.
Crucial recommendations for user safety
Cybersecurity experts advise the immediate installation of available updates for all Apple devices. On iPhone or iPad, the process is simple: go to Ajustes > Geral > Atualização from Software to check and apply the new versions.
For Macs, users must access Preferências from Sistema or the menu from Configurações to check for pending updates and ensure the system is protected. It’s important to note that older devices also receive extended support releases, such as iOS 18.7.3, to ensure that security isn’t overlooked on more dated equipment.
Maintaining regular backups of all data complements protection measures, offering an extra layer of security in case of incidents. Além Furthermore, avoiding clicking on suspicious links or opening unknown email attachments continues to be a fundamental practice to reduce the risks of exploitation via the web. US Agência of Cibersegurança (CISA) added one of the patched flaws to its catalog of known exploited vulnerabilities, underlining the urgency of updates.
Follow: all about Apple security
Evolution of threats to Apple devices
Exploiting flaws in WebKit continues to be a common tactic in targeted attacks, especially those carried out by groups with advanced capabilities and specific objectives. In previous years, similar vulnerabilities were used to facilitate the installation of surveillance and spyware tools on high-profile devices.
Apple’s ability to quickly respond to these threats is crucial to limiting the impact of exploitation campaigns. The focus on sophisticated attacks suggests that targets are often high-profile individuals such as journalists, human rights activists or political figures, making protection even more vital.
Continuous monitoring, both by Apple’s internal security teams and external researchers, is a determining factor in the efficient detection and rapid mitigation of these vulnerabilities. Essa constant vigilance allows the company to stay ahead of attack tactics and protect its users effectively.

