{"id":344414,"date":"2025-12-14T09:46:13","date_gmt":"2025-12-14T09:46:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/344414\/"},"modified":"2025-12-14T09:46:13","modified_gmt":"2025-12-14T09:46:13","slug":"apple-confirms-attacks-all-iphone-users-must-update-now-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/344414\/","title":{"rendered":"Apple Confirms Attacks\u2014All iPhone Users Must Update Now"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/12\/1765705573_969_0x0.jpg\" alt=\"Apple IOS 26 Update\" data-height=\"1540\" data-width=\"2311\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>Confirmation of iPhone attacks.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Updated on Dec. 13 with additional analysis of the new attack warning.<\/p>\n<p>Apple has just <a class=\"color-link\" href=\"https:\/\/support.apple.com\/en-us\/125884\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/support.apple.com\/en-us\/125884\" aria-label=\"warned\">warned<\/a> that two iPhone vulnerabilities \u201cmay have been exploited in an extremely sophisticated attack against specific targeted individuals.\u201d It follows this month\u2019s <a class=\"color-link\" href=\"https:\/\/www.reuters.com\/technology\/apple-sent-new-round-cyber-threat-notifications-users-84-countries-2025-12-05\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.reuters.com\/technology\/apple-sent-new-round-cyber-threat-notifications-users-84-countries-2025-12-05\/\" aria-label=\"spyware\">spyware<\/a> warnings, issued to iPhone users around the world. <\/p>\n<p>Both vulnerabilities have now been fixed in <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/apple-ios-262-release-date-critical-update-for-1-billion-iphones\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/apple-ios-262-release-date-critical-update-for-1-billion-iphones\/\" target=\"_self\" aria-label=\"iOS 26.2\" rel=\"nofollow noopener\">iOS 26.2<\/a>, released today. But while the update now message applies to users already running iOS 26, there\u2019s a more serious warning for those yet to upgrade. These attacks targeted individuals \u201con versions of iOS before iOS 26.\u201d And even though iOS 18 is still being patched, it\u2019s not worth the risk. <\/p>\n<p>Apple wants you to upgrade. You should do exactly that.Apple has disclosed that the two vulnerabilities are linked. CVE-2025-14174 and CVE-2025-43529 were both \u201cissued in response to this report.\u201d One is attributed to Google\u2019s Threat Analysis Group, the other to Google\u2019s threat hunters and Apple itself. <\/p>\n<p>And both affect WebKit. One, Apple says, risks a browser \u201cprocessing maliciously crafted web content (that) may lead to arbitrary code execution.\u201d While the other \u201cmay lead to memory corruption.\u201d This has the hallmarks of a chained spyware attack.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-0\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/it-may-be-worse-no-fix-for-new-threat-to-google-chrome-users\/\" target=\"_blank\" aria-label=\"\u2018It May Be Worse\u2019\u2014No Fix For New Google Chrome Attacks\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/it-may-be-worse-no-fix-for-new-threat-to-google-chrome-users\/\" rel=\"nofollow noopener\">Forbes\u2018It May Be Worse\u2019\u2014No Fix For New Google Chrome AttacksBy Zak Doffman<\/a><\/p>\n<p>According to Ali Mousavifar from Menlo Security, \u201cthe two active WebKit exploits in iOS 26.2 highlight a clear trend: browser engines are a primary target for attackers. We should expect these types of attacks to continue as the browser becomes the center of modern work. Relying solely on patching is a reactive game.\u201d<\/p>\n<p>\u201cIn all probability, these vulnerabilities have been chained to achieve exploitation,\u201d Mayuresh Dani from Qualys told me. \u201cWebKit has a well-documented history of serving as the primary entry point for sophisticated spyware and surveillance campaigns.\u201d That includes \u201cnow infamous monitoring spywares such as Pegasus, which have consistently relied on WebKit vulnerabilities as its primary attack vector.\u201d<\/p>\n<p>Dani says iPhone users must \u201cfollow operational security practices, such as updating to iOS 26.2 immediately, using iCloud Private Relay to mask their IP and encrypt DNS queries (and) also as a practice, users should enable private browsing and disable JavaScript temporarily while interacting with untrusted sites.\u201d<\/p>\n<p>The two exploited vulnerabilities are amongst eight WebKit threats patched in this release. Others are various types of memory mishandling, which opens the door to destabilizing an app or the OS, potentially allowing other types of exploits to be used. Again, just more reasons to ensure you install the update as soon as it shows available.<\/p>\n<p>We have seen WebKit <a class=\"color-link\" href=\"https:\/\/socprime.com\/blog\/cve-2025-24201-webkit-zeroday-vulnerability\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/socprime.com\/blog\/cve-2025-24201-webkit-zeroday-vulnerability\/\" aria-label=\"zero-day attacks\">zero-day attacks<\/a> before. It\u2019s a <a class=\"color-link\" href=\"https:\/\/www.darkreading.com\/mobile-security\/apple-drops-another-webkit-zero-day-bug\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.darkreading.com\/mobile-security\/apple-drops-another-webkit-zero-day-bug\" aria-label=\"prime target\">prime target<\/a> for spyware developers building and marketing exploits. These latest vulnerabilities can be added to the \u201c<a class=\"color-link\" href=\"https:\/\/www.darkreading.com\/mobile-security\/apple-drops-another-webkit-zero-day-bug\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.darkreading.com\/mobile-security\/apple-drops-another-webkit-zero-day-bug\" aria-label=\"17 zero-day bugs in WebKit that attackers have exploited in the wild\">17 zero-day bugs in WebKit that attackers have exploited in the wild<\/a>\u201d since 2023. And while these are targeted at very specific individuals, vulnerabilities have a nasty habit of getting into the wild and spreading further down the food chain.<\/p>\n<p>\u201cUsers should urgently update all their impacted Apple devices,\u201d James Maude from BeyondTrust warns. \u201cEven though this only appears to be linked to a small number of targeted attacks it will quickly become a must have exploit for a range of threat actors.\u201d<\/p>\n<p>There is a further risk to users beyond the two exploited vulnerabilities, now that iOS 26\u2019s fixes are in the public domain. For example, \u201can app may be able to access sensitive user data\u201d in Messages or \u201cpassword fields may be unintentionally revealed when remotely controlling a device over FaceTime.\u201d <\/p>\n<p>At the beginning of December, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/01\/within-48-hours-google-issues-critical-update-for-all-android-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/01\/within-48-hours-google-issues-critical-update-for-all-android-users\/\" target=\"_self\" aria-label=\"Google also warned that its OS was under attack\" rel=\"nofollow noopener\">Google also warned that its OS was under attack<\/a>. Again it was two vulnerabilities that were being exploited in the wild to target Android users. It rushed out an emergency update within hours and <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/04\/google-issues-critical-update-for-all-pixel-users-attacks-confirmed\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/04\/google-issues-critical-update-for-all-pixel-users-attacks-confirmed\/\" target=\"_self\" aria-label=\"Pixels were patched\" rel=\"nofollow noopener\">Pixels were patched<\/a> within days. <\/p>\n<p>Dani explains \u201cthe two critical WebKit vulnerabilities are memory safety violations that Apple confirms were weaponized in real-world targeted attacks against specific individuals on pre-iOS 26 devices. CVE-2025-43529 allows threat actors a direct code execution capability, while CVE-2025-14174 provides the much needed sandbox escape and privilege escalation capabilities which makes it devastating.\u201d<\/p>\n<p>The other notable vulnerability beyond WebKit, per <a class=\"color-link\" href=\"https:\/\/cyberpress.org\/iphone-zero-day-vulnerabilities\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/cyberpress.org\/iphone-zero-day-vulnerabilities\/\" aria-label=\"Cyber Press\">Cyber Press<\/a>, is \u201c a critical Kernel issue (CVE-2025-46285) in which a malicious app could gain root privileges due to an integer overflow bug. The fix involves adopting 64-bit timestamps to prevent privilege escalation exploits. Another serious flaw in the App Store (CVE-2025-46288) could have allowed apps to access sensitive payment tokens, exposing financial data; this issue is now fixed with stricter permission controls.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/samsung-surprises-millions-of-galaxy-users-with-emergency-update\/\" target=\"_blank\" aria-label=\"Samsung Surprises Millions Of Users With Emergency Android Update\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/12\/samsung-surprises-millions-of-galaxy-users-with-emergency-update\/\" rel=\"nofollow noopener\">ForbesSamsung Surprises Millions Of Users With Emergency Android UpdateBy Zak Doffman<\/a><\/p>\n<p>Maude warns \u201cWebKit is the underpinning for every iOS browser and many apps as Apple requires it to be used for apps in their store. Every browser uses the same WebKit rendering engine layering additional functionality layer on top . While this allows them to control the ecosystem, it also creates an inherent point of failure. If Webkit is vulnerable your entire device could be vulnerable when viewing content online.\u201d<\/p>\n<p>This isn\u2019t the first time we\u2019ve seen Android and iPhone attacks disclosed and addressed the same month. Both operating systems are being attacked by the same mercenary spyware industry, so it should be no surprise. Both Apple and Google have done a good job in rushing out fixes to everyone, everywhere. The caveat on the Android side is that this only works for Pixels. Other OEMs \u2014 <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/10\/google-confirms-android-attacks-no-fix-for-most-samsung-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/10\/google-confirms-android-attacks-no-fix-for-most-samsung-users\/\" target=\"_self\" aria-label=\"Samsung for example\" rel=\"nofollow noopener\">Samsung for example<\/a> \u2014 cannot do the same.<\/p>\n<p>America\u2019s cyber defense agency <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/02\/cisa-warns-samsung-and-pixel-users-update-or-stop-using-your-phone\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/12\/02\/cisa-warns-samsung-and-pixel-users-update-or-stop-using-your-phone\/\" target=\"_self\" aria-label=\"issued its own warning\" rel=\"nofollow noopener\">issued its own warning<\/a> following the Android release. We can almost certainly expect the same for Apple users by the beginning of next week.<\/p>\n<p>\u201cThere\u2019s no workaround or user behavior that meaningfully mitigates this risk,\u201d says Keeper Security\u2019s Darren Guccione. Installing the update \u201cis the only effective defense. Once patches are public, the exposure window widens for anyone who delays updating.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Confirmation of iPhone attacks. NurPhoto via Getty Images Updated on Dec. 13 with additional analysis of the new&hellip;\n","protected":false},"author":2,"featured_media":342807,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[113383,149794,49,48,121919,123160,149793,113381,61],"class_list":["post-344414","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apple-attack","tag-apple-update-now-warning","tag-ca","tag-canada","tag-ios-26-vs-ios-18","tag-ios-26-2","tag-iphone-spyware-attack","tag-iphone-update-warning","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/344414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=344414"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/344414\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/342807"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=344414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=344414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=344414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}