Apple has issued emergency security updates to address two significant zero-day vulnerabilities within WebKit, the browser engine for Safari and iOS browsers. The flaws, identified as CVE-2025-43529 and CVE-2025-14174, were exploited in targeted attacks against specific individuals, indicating a sophisticated threat likely associated with spyware rather than broad cybercrime.
Both vulnerabilities allow attackers to execute arbitrary code or corrupt memory when devices access malicious web content. CVE-2025-43529 was discovered by Google's Threat Analysis Group, which often signals involvement from nation-state or commercial spyware actors. Apple has confirmed that these vulnerabilities affected versions of iOS prior to iOS 26.
In light of this security concern, users are advised to update their devices immediately to mitigate risks. The nature of these attacks, focusing on a limited number of targets, highlights the importance of vigilance against online threats.