Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Apple Patches Two Zero-Days Tied to Mysterious Exploited Chrome Flaw

Apple has released macOS and iOS updates to patch two WebKit zero-days exploited in an “extremely sophisticated” attack.

Apple patches

Apple has released macOS and iOS updates to patch dozens of vulnerabilities, including two zero-days that the tech giant says have been exploited in highly targeted attacks.

According to Apple’s advisories, the zero-days impact WebKit, the browser engine present in Safari, iOS, iPadOS, macOS, tvOS, watchOS, and visionOS.

One of the zero-days, CVE-2025-14174, has been described as a memory corruption issue, while the second, CVE-2025-43529, is a use-after-free bug. They can both be exploited using maliciously crafted web content to execute arbitrary code. 

Apple announced patches for CVE-2025-14174 and CVE-2025-43529 with the release of iOS and iPadOS 26.2, iOS and iPadOS 18.7.3, macOS Tahoe 26.2, Safari 26.2 for macOS, tvOS 26.2, watchOS 26.2, and visionOS 26.2.

However, Apple’s advisories clarify that the vulnerabilities have been exploited in “an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26”.

The tech giant said the vulnerabilities were discovered by its own security team and Google’s Threat Analysis Group.

Advertisement. Scroll to continue reading.

This, along with the brief description of the attacks, indicates that the zero-days have likely been exploited by commercial spyware vendors, which are known to target Android, iOS, macOS, Chrome, and WhatsApp.

CVE-2025-14174 is the mysterious Chrome zero-day

Google last week announced patches for a mysterious Chrome zero-day. The company said it had seen an exploit in the wild, but the flaw initially did not have a CVE identifier or any description, other than a ‘high severity’ rating.

Google has now updated its original advisory to clarify that the previously unidentified zero-day is CVE-2025-14174. 

The company says the security hole is an out-of-bounds memory access issue in the Angle graphics library. Because Angle is used by both Chrome’s Blink browser engine and WebKit, the zero-day impacts both Google and Apple products.

It appears Google and Apple have been coordinating the disclosure and patching of the vulnerability. According to Google’s advisory, the issue came to light on December 5.

Google has not shared any information on attacks targeting Chrome users.

It’s also worth noting that the Angle library is used by Chromium, and other Chromium-based browsers such as Edge, Opera, Vivaldi, and Brave are impacted as well. 

Microsoft has already updated Edge to address CVE-2025-14174. Vivaldi has also been updated to patch the zero-day. 

CISA has added CVE-2025-14174 to its Known Exploited Vulnerabilities (KEV) catalog. 

Related: Apple Patches Zero-Day Exploited in Targeted Attacks

Related: CISA Warns of Spyware Targeting Messaging App Users

Related: Landfall Android Spyware Targeted Samsung Phones via Zero-Day

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.