Article Details

Scrape Timestamp (UTC): 2026-02-12 05:43:28.220

Source: https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html

Original Article Text

Click to Toggle View

Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices. Apple on Wednesday released iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS updates to address a zero-day flaw that it said has been exploited in sophisticated cyber attacks. The vulnerability, tracked as CVE-2026-20700 (CVSS score: N/A), has been described as a memory corruption issue in dyld, Apple's Dynamic Link Editor. Successful exploitation of the vulnerability could allow an attacker with memory write capability to execute arbitrary code on susceptible devices. Google Threat Analysis Group (TAG) has been credited with discovering and reporting the bug. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26," the company said in an advisory. "CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report." It's worth noting that both CVE-2025-14174 and CVE-2025-43529 were addressed by Cupertino in December 2025, with the former first disclosed by Google as having been exploited in the wild. CVE-2025-14174 (CVSS score: 8.8) relates to an out-of-bounds memory access in ANGLE's Metal renderer component. Metal is a high-performance hardware-accelerated graphics and compute API developed by Apple. CVE-2025-43529 (CVSS score: 8.8), on the other hand, is a use-after-free vulnerability in WebKit that may lead to arbitrary code execution when processing maliciously crafted web content. The updates are available for the following devices and operating systems - In addition, Apple has also released updates to resolve various vulnerabilities in older versions of iOS, iPadOs, macOS, and Safari - With the latest development, Apple has moved to address its first actively exploited zero-day in 2026. Last year, the company patched nine zero-day vulnerabilities that were exploited in the wild.

Daily Brief Summary

VULNERABILITIES // Apple Patches Zero-Day Exploited in Sophisticated Cyber Attacks

Apple released updates for iOS, macOS, and other platforms to fix a zero-day flaw exploited in targeted cyber attacks.

The vulnerability, CVE-2026-20700, involves memory corruption in Apple's Dynamic Link Editor, potentially enabling arbitrary code execution.

Google’s Threat Analysis Group discovered the flaw, contributing to Apple's swift response in addressing the security issue.

Apple also addressed CVE-2025-14174 and CVE-2025-43529, both previously exploited and patched in late 2025.

CVE-2025-14174 involves out-of-bounds access in ANGLE's Metal renderer, while CVE-2025-43529 is a use-after-free flaw in WebKit.

The updates cover a broad range of devices, including older versions, enhancing overall security across Apple's ecosystem.

This marks Apple's first actively exploited zero-day patch in 2026, following nine similar vulnerabilities addressed in 2025.