web analytics

Apple patches zero-day bugs used in targeted iPhone attacks – Source: www.csoonline.com

Rate this post

Source: www.csoonline.com – Author:

The bug was reportedly exploited in “extremely sophisticated” attacks against targeted individuals.

Apple has rolled out emergency patches for a bug affecting Webkit, the open-source web browser engine used primarily in Safari, against active exploitations in the wild.

The vulnerability, CVE-2025024201, was reportedly exploited in zero-day attacks against targeted individuals.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before 17.2,” the iPhone maker said in an advisory.

Patches were released on Tuesday and are available through the latest versions of iOS, iPadOS, macOS, Safari, and visionOS.

An out-of-bounds write issue

The vulnerability specifically affects Apple’s Web Content Sandbox feature, a security mechanism that isolates web content from the rest of the system, preventing malicious websites from accessing sensitive data or executing harmful code beyond the browser environment.

“Maliciously crafted web content may be able to break out of Web Content sandbox,” Apple added. This is an out-of-bounds write issue that Apple first fixed in iOS 17.2 while blocking the zero-day attempts.

The company has now rolled out supplementary fixes for all the affected operating systems. Updates with patches include iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, and vision 2.3.2.

While Apple refrained from disclosing technical details of the exploitation for security reasons, it is known that such issues could potentially allow high-impact attacks, including remote code execution (RCE), privilege escalation, data theft, and device takeover.

Although the bug was reported to be used only in targeted attacks, all Apple users are advised to install these updates promptly, as they may be used in other attacks.

Three zero-days within months

This marks Apple’s third zero-day fix since the start of the year, following patches for CVE-2025-24085 in January and CVE-2025-24200 in February.

Apple’s leading market share attracts frequent adversarial interest, making a development or configurational mishap extremely punishing. The company suffered a total of twenty bugs in 2023, including the RCE bugs, CVE-2023-32434 and CVE-2023-32435 allegedly exploited in the Operation Triangulation spy campaign.

In 2024, Apple fixed six zero-day bugs, along with a string of critical flaws including CVE-2024-23225 and CVE-2024-23296 which together allowed attackers to bypass kernel memory protection.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.

Original Post url: https://www.csoonline.com/article/3843999/apple-patches-zero-day-bugs-used-in-targeted-iphone-attacks.html

Category & Tags: Browser Security, Security, Vulnerabilities – Browser Security, Security, Vulnerabilities

Views: 2

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post