Trending

Apple Patches WebKit Zero-Day Exploited in Targeted Attacks

Listen to this article

Apple has released a security update to patch a zero-day vulnerability that has been actively exploited in what it describes as “extremely sophisticated” attacks.

The flaw, identified as CVE-2025-24201, resides in the WebKit browser engine and is classified as an out-of-bounds write issue. Attackers could leverage this vulnerability to craft malicious web content capable of escaping the Web Content sandbox.

Apple addressed the issue by implementing improved validation checks. The company also clarified that this fix is an extension of a previous mitigation introduced in iOS 17.2. It further noted that the exploit may have been used in targeted attacks against specific individuals running iOS versions prior to 17.2.

However, Apple did not disclose details about when the attacks began, their duration, or the identity of the affected targets. The advisory also does not specify whether the vulnerability was discovered internally or reported by an external researcher.

Devices and OS Versions Receiving the Update:

With this latest fix, Apple has now patched three actively exploited zero-days in its software this year, the previous two being CVE-2025-24085 and CVE-2025-24200.

Cyberkitera is a premier cybersecurity publishing platform dedicated to providing the latest insights, expert security tips, and news across all areas of cybersecurity. Our mission is to empower individuals and businesses with knowledge to prevent cyber threats, stay informed about emerging trends, and safeguard their digital assets. From industry updates to practical advice on protecting against cyber attacks, Cyberkitera is your trusted source for staying ahead in the ever-evolving world of cybersecurity.

Post Comment