Apple patches 0-day exploited in “extremely sophisticated attack”

You May Be Interested In:Cloudflare turns AI against itself with endless maze of irrelevant facts



Apple on Tuesday patched a critical zero-day vulnerability in virtually all iPhones and iPad models it supports and said it may have been exploited in “an extremely sophisticated attack against specific targeted individuals” using older versions of iOS.

The vulnerability, tracked as CVE-2025-24201, resides in Webkit, the browser engine driving Safari and all other browsers developed for iPhones and iPads. Devices affected include the iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later. The vulnerability stems from a bug that wrote to out-of-bounds memory locations.

Supplementary fix

“Impact: Maliciously crafted web content may be able to break out of Web Content sandbox,” Apple wrote in a bare-bones advisory. “This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)”

The advisory didn’t say if the vulnerability was discovered by one of its researchers or by someone outside the company. This attribution often provides clues about who carried out the attacks and who the attacks targeted. The advisory also didn’t say when the attacks began or how long they lasted.

The update brings the latest versions of both iOS and iPadOS to 18.3.2. Users facing the biggest threat are likely those who are targets of well-funded law enforcement agencies or nation-state spies. They should install the update immediately. While there’s no indication that the vulnerability is being opportunistically exploited against a broader set of users, it’s a good practice to install updates within 36 hours of becoming available.

share Paylaş facebook pinterest whatsapp x print

Similar Content

New Scientist. Science news and long reads from expert journalists, covering developments in science, technology, health and the environment on the website and the magazine.
Quantum computers have finally arrived, but will they ever be useful?
The Google Gemini logo.
Google is about to make Gemini a core part of Workspaces—with price changes
Competition opens to find the world's most perplexing computer code
Competition opens to find the world’s most perplexing computer code
Microsoft posts a record $29.1 billion Q1. Same old, same old
Microsoft posts a record $29.1 billion Q1. Same old, same old
2SA3JYH Various Artificial Intelligence mobile apps, DeepSeek open-source large language models app on January 28, 2025 in Prague, Czech Republic.
DeepSeek has burst the AI hype bubble – now all bets are off
You can love or hate AI, but it’s killed crappy 8GB versions of pricey PCs and Macs
You can love or hate AI, but it’s killed crappy 8GB versions of pricey PCs and Macs
The News Spectrum | © 2025 | News