Security patches roll out across iOS, macOS, and Apple platforms to neutralize active exploits targeting WebKit browser engine.
Two Actively Exploited Vulnerabilities Prompt Rapid Patch Release
Apple on December 12, 2025, released a sweeping set of security updates for iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari to address two critical WebKit vulnerabilities that the company says “may have been exploited in the wild” in highly targeted attacks.`
The flaws — tracked as CVE-2025-43529 and CVE-2025-14174 — reside in WebKit, the browser rendering engine that underpins Safari and all third-party browsers on Apple platforms. WebKit vulnerabilities are especially serious because they can be leveraged simply through malicious web content without requiring user interaction beyond visiting a crafted page — a technique commonly used in advanced spyware campaigns.
According to Apple, the vulnerabilities affect devices running older OS versions prior to iOS 26 and could lead to arbitrary code execution or memory corruption when processing maliciously crafted content.
Details of the Vulnerabilities and Affected Systems
The first flaw, CVE-2025-43529, is a use-after-free issue in WebKit that may allow attackers to execute arbitrary code. The second, CVE-2025-14174, is a memory corruption bug with a high severity profile, also within WebKit. Notably, the latter was the same flaw Google patched earlier this week in its Chrome browser after detecting exploitation in the wild.
Security teams credited with uncovering and reporting the bugs include Apple Security Engineering and Architecture (SEAR) and Google’s Threat Analysis Group (TAG) — a unit renowned for its work tracking sophisticated and often nation-state-linked threat activity.
The breadth of Apple products updated demonstrates the reach of the issue:
- iOS 26.2 and iPadOS 26.2
- macOS Tahoe 26.2
- tvOS 26.2
- watchOS 26.2
- visionOS 26.2
- Safari 26.2
Older supported OS versions also received fixes to ensure legacy devices were protected.
This marks the ninth zero-day vulnerability Apple has patched in 2025 that was exploited in real-world attacks, joining previous fixes for high-profile issues including CVE-2025-24085, CVE-2025-31200, and CVE-2025-43300.
Why WebKit Vulnerabilities Are Critical
WebKit plays a crucial role across Apple’s ecosystem: it powers Safari and acts as the underlying web engine for third-party browsers on iPhone and iPad. Because Apple’s platform policies require all browsers on iOS to use WebKit, a vulnerability here impacts every browser app running on those devices, exponentially increasing the potential attack surface.
Malicious actors can exploit these kinds of flaws by embedding harmful scripts in web pages or content that targets specific individuals — a method frequently associated with mercenary spyware operations. In recent years, WebKit bugs have been tied to precise, targeted attacks against activists, journalists, and high-value targets, underscoring the real-world risk beyond theoretical vulnerability.
Industry and Expert Perspectives
While Apple’s official advisories do not always disclose detailed technical specifics — a deliberate choice meant to curb further exploitation before patches are widely adopted — security experts caution that any public acknowledgment of in-the-wild exploitation increases risk. Once attackers know a flaw exists and see it documented, they may accelerate attempts to weaponize it if targets have not patched promptly.
Google’s involvement, through TAG, further signals the seriousness of these flaws. TAG researchers focus on uncovering vulnerabilities that are actively leveraged by advanced persistent threats, including state-linked actors. That Apple credited TAG for finding one of the bugs adds weight to speculation that these were not run-of-the-mill security issues but likely tied to precision intrusion campaigns.
Security professionals recommend that organizations and individual users treat this update as urgent, applying patches immediately and enabling automatic updates where possible to guard against exploitation. The rapid timeline between discovery, disclosure, and patch availability is indicative of the severity and active nature of these threats.
Conclusion: Update Without Delay
The latest Apple security updates underscore a stark reality: even mature, tightly audited platforms are not immune to vulnerabilities — particularly when threat actors are determined and well-resourced. With both Apple and Google documenting exploitation of the same underlying WebKit flaw, users face a rare cross-ecosystem risk that demands swift action.
For consumers and enterprises alike, the message from security teams is clear: update your devices immediately. Delaying patches in the face of verified in-the-wild exploitation leaves data, identities, and devices unnecessarily exposed.
Please subscribe to the Newsletter so that you do not miss any critical update
