Apple disclosed and patched two critical WebKit vulnerabilities, CVE-2025-43529 and CVE-2025-14174, that could allow attackers to execute code via Safari and potentially gain broad access to affected iPhones and iPads, including sensitive data such as passwords and financial information. Reporting describes the issues as zero-click/low-interaction style browser exploitation stemming from memory-handling flaws in WebKit, with claims they were exploited as zero-days in the wild prior to Apple’s fixes.
The fixes are reported as delivered in iOS 26, creating exposure risk for users who have not upgraded and for devices that cannot move beyond older iOS/iPadOS versions; multiple sources cite slow adoption of iOS 26, leaving a large population potentially unpatched. Separate coverage encouraging upgrades to iOS 26 frames security as a primary driver (patching “nasty security bugs”), reinforcing the operational takeaway for enterprises: accelerate iOS 26 rollout where supported, and apply compensating controls (e.g., device refresh planning, stricter web content controls, and MDM-enforced update compliance) for fleets that cannot upgrade.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Apple urged users on supported iPhone and iPad models to install the latest operating system updates to receive fixes for the critical WebKit flaws. The reports noted that devices unable to upgrade to iOS 26 remain exposed to these issues.
Subsequent iOS 26 point releases—26.0.1, 26.1, and 26.2—collectively addressed numerous vulnerabilities beyond the initial iOS 26 release. iOS 26.2 also improved AirDrop security by requiring one-time codes for transfers to non-contacts beyond the previous 10-minute window.
Apple issued iOS 26 security updates that patched CVE-2025-43529 and CVE-2025-14174, two WebKit vulnerabilities described as part of a zero-click/zero-day Safari exploitation chain. Apple said the flaws had been exploited in the wild against targeted individuals on pre-iOS 26 versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.