Apple fixes dangerous zero-day used in attacks against iPhones and iPads
techradar.com
- Apple released a new fix for iOS and iPadOS
- It solves a zero-day used in "extremely sophisticated" attacks
- This is the third zero-day addressed this year
Apple has released a new patch for iOS and iPadOS addressing a vulnerability abused in “extremely sophisticated” attacks. In a security advisory published earlier this week, the company said it recently uncovered an out-of-bounds write issue in WebKit, its cross-platform web browser engine.
WebKit is used by Apple’s browser, Safari, as well as other apps and browsers on macOS, iOS, Linux, and Windows.
The vulnerability is tracked as CVE-2025-24201, and can be used to break out of the Web Content sandbox through custom-built web content. It is yet to be assigned a severity score.
ConnectWise RAT
Apparently, the vulnerability was fixed in iOS 17.2, but can still be exploited in older models: "This is a supplementary fix for an ...
Copyright of this story solely belongs to techradar.com . To see the full text click HERE