Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks – The Hacker News




Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks - The Hacker News

🔍 Summary:

Apple has issued a security update to fix a critical zero-day vulnerability in its WebKit web browser engine, identified as CVE-2025-24201. This flaw, an out-of-bounds write issue, could potentially allow attackers to execute malicious web content outside the Web Content sandbox, posing a significant security risk. The vulnerability, which Apple described as part of “extremely sophisticated” attacks, was addressed with enhanced security checks. This update acts as an additional measure to a previously blocked attack in iOS 17.2 and was noted to have been exploited in targeted attacks on earlier iOS versions. Apple’s advisory did not disclose the origin of the flaw’s discovery, the duration of the attacks, or the identities of the targeted individuals. The security patch is part of Apple’s ongoing efforts to secure its devices, marking the third zero-day vulnerability addressed by the company this year. The update is available for various devices and operating system versions, ensuring broader protection for users.

📌 Source: https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html

위로 스크롤