Article Details

Scrape Timestamp (UTC): 2025-03-12 04:10:44.344

Source: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html

Original Article Text

Click to Toggle View

Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks. Apple on Tuesday released a security update to address a zero-day flaw that it said has been exploited in "extremely sophisticated" attacks. The vulnerability has been assigned the CVE identifier CVE-2025-24201 and is rooted in the WebKit web browser engine component. It has been described as an out-of-bounds write issue that could allow an attacker to craft malicious web content such that it can break out of the Web Content sandbox. Apple said it resolved the issue with improved checks to prevent unauthorized actions. It also noted that it's a supplementary fix for an attack that was blocked in iOS 17.2. Furthermore, it acknowledged that the vulnerability "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2." However, the advisory does not mention if Apple's own security team discovered the flaw or if it was reported to it by an external researcher. It also does not mention when the attacks began, how long they lasted, and who was targeted. The update is available for the following devices and operating system versions - With the latest development, Apple has addressed a total of three actively exploited zero-days in its software since the start of the year, the other two being CVE-2025-24085 and CVE-2025-24200.

Daily Brief Summary

MALWARE // Apple Updates iOS to Mitigate WebKit Zero-Day Exploitation

Apple released a patch for a zero-day flaw in WebKit, identified as CVE-2025-24201.

The vulnerability allowed highly sophisticated cyber attacks via malicious web content.

It affected earlier iOS versions before 17.2, aiming at specific targeted individuals.

The flaw was an out-of-bounds write issue risking sandbox escape in the web content.

The patch includes improved checks to enhance security and prevent unauthorized actions.

Apple's security update is crucial as it includes fixes for three zero-days exploited this year.

Devices running on older iOS versions were urged to update to receive protection.

Details about the discovery of the flaw or the duration and specifics of the attacks remain undisclosed.