New Update Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,677
Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in "extremely sophisticated" attacks.

The vulnerability is tracked as CVE-2025-24201 and was found in the WebKit cross-platform web browser engine used by Apple's Safari web browser and many other apps and web browsers on macOS, iOS, Linux, and Windows.

"This is a supplementary fix for an attack that was blocked in iOS 17.2," the iPhone maker said in security advisories issued on Tuesday. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2."

Apple said attackers can exploit the CVE-2025-24201 vulnerability using maliciously crafted web content to break out of the Web Content sandbox.

The company has fixed this out-of-bounds write issue with improved checks to prevent unauthorized actions in iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2, and Safari 18.3.1.
 

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,677
Apple Releases iOS 18.3.2 and macOS Sequoia 15.3.2
Apple has just released new security updates for iPhone, iPad, and Mac users in the form of iOS 18.3.2, iPadOS 18.3.2, and macOS Sequoia 15.3.2. The release notes for these updates only “important bug fixes” and security updates, and there’s also a fix for an issue that may prevent the playback of some streaming content on iPhones and iPads.

9to5Mac also reports that visionOS 2.3.2 and tvOS 18.3.2 are also available to download today, but the release notes for these updates are not live yet. You probably shouldn’t expect any big changes, however.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top