The technology giant has released a vital security suite to patch vulnerabilities actively exploited by hackers. The measure aims to close loopholes in the browsing engine that could allow the remote installation of malicious software on the brand’s mobile devices and computers. The update reaches users to mitigate severe risks associated with the processing of web content, ensuring the integrity of personal data stored on devices.
Cybersecurity experts identified that the flaws allowed arbitrary code execution, which in practice gives attackers partial or total control of the system without the owner’s consent. The fix was distributed globally to prevent digital espionage campaigns from continuing to use these gateways to compromise the privacy of specific targets, such as journalists and activists.
Critical vulnerabilities in the WebKit engine
The central focus of this update lies on WebKit, the rendering engine that powers the Safari browser and serves as the foundation for all browsers enabled in the company’s mobile ecosystem. The flaws officially cataloged as CVE-2025-43529 and CVE-2025-14174 involve memory management issues that occur when the device processes malicious web content. When accessing a page designed for attack, the system could suffer a buffer overflow, opening the way for the injection of external commands.
The severity of the situation is amplified by the fact that these are “zero-day” flaws, meaning that cybercriminals discovered and exploited the error before system developers could create a defense. Official recognition that these vulnerabilities may have been exploited in real attacks accelerated the software release schedule, skipping traditional lengthy beta testing steps to prioritize immediate shielding of operating systems.
Learn more: New Apple system update optimizes urgent task management for iPhone users
Affected devices and available versions
The scope of this security fix is vast, covering the latest product lines and offering extended support for older models. For users with newer hardware, iOS 26.2 is now available for download and installation. The package also includes iPadOS for tablets and macOS Tahoe 26.2 for the Mac line of computers, ensuring that the ecosystem is uniformly protected.
Recognizing that many consumers still use devices that do not support the latest operating system, iOS 18.7.3 and iPadOS 18.7.3 have been made available. Essa strategy ensures that devices such as the iPhone 15 and previous models of iPad Pro and iPad Air are not left unprotected against the same threats, maintaining the policy of long-term support for legacy hardware.
Attack and prevention mechanisms
The attack vector used in these vulnerabilities is particularly dangerous because it does not require complex interaction from the victim. Basta allows the user to browse a compromised website or receive manipulated web data packets so that the exploit is activated. Once executed, the malicious code can install spyware capable of monitoring communications, tracking location and accessing private files, operating silently in the background.
On the same topic: Tim Cook reveals new iPhone and iPod prototypes in celebration of Apple’s fiftieth anniversary
To mitigate these risks, the update implements stricter health checks on WebKit’s memory processing. Além In addition, the operating system reinforced process isolation, making it difficult for a flaw in the browser to escalate privileges to reach the core of the system or access data from other banking and social applications installed on the device.
Recommendations and Modo of Bloqueio
Immediate patch installation is the default recommendation for all users, and can be carried out through the system settings menu. Para individuals who consider themselves to be at high risk from targeted attacks by mercenary spyware, enabling “Bloqueio Mode” provides an additional layer of defense. Este feature severely restricts certain functionality, such as previewing links and attachments and executing complex web scripts, drastically reducing the attack surface available to hackers.
The company reinforces that keeping software up to date is the most effective barrier against modern cybercrime. With the increasing sophistication of hacking tools, the time window between the discovery of a flaw and its mass exploitation has decreased, making agility in applying updates an essential habit for personal and corporate digital security.
More on this story: Apple launches 5.5mm iPhone 17 Air with full locking of parts and fluid interface

