Tech »  Topic »  Apple fixes dangerous zero-day used in attacks against iPhones and iPads

Apple fixes dangerous zero-day used in attacks against iPhones and iPads


(Image credit: Future)
  • Apple released a new fix for iOS and iPadOS
  • It solves a zero-day used in "extremely sophisticated" attacks
  • This is the third zero-day addressed this year

Apple has released a new patch for iOS and iPadOS addressing a vulnerability abused in “extremely sophisticated” attacks. In a security advisory published earlier this week, the company said it recently uncovered an out-of-bounds write issue in WebKit, its cross-platform web browser engine.

WebKit is used by Apple’s browser, Safari, as well as other apps and browsers on macOS, iOS, Linux, and Windows.

The vulnerability is tracked as CVE-2025-24201, and can be used to break out of the Web Content sandbox through custom-built web content. It is yet to be assigned a severity score.

ConnectWise RAT

Apparently, the vulnerability was fixed in iOS 17.2, but can still be exploited in older models: "This is a supplementary fix for an ...


Copyright of this story solely belongs to techradar.com . To see the full text click HERE