Apple rushes out update for two WebKit zero-days

Apple has released emergency patches for two WebKit zero-days, CVE-2025-43529 (a use-after-free) and CVE-2025-14174 (memory corruption). Both can be exploited through maliciously crafted web content to run arbitrary code on the device. The flaws were found by Google's Threat Analysis Group and, according to Apple, were used in extremely sophisticated targeted attacks against specific individuals running releases earlier than iOS 26. WebKit is the engine behind browsers on iOS and iPadOS, including those not named Safari.

What this means for your organisation

Attacks of this kind are aimed at named individuals, not at volume. In a Norwegian context that means executives, board members, lawyers, journalists and staff with access to negotiations or sensitive cases. A successful attack gives access to the phone, and with it email, messages and MFA codes. Because the flaws affect every browser on iOS, "we don't use Safari" is not a defence.

Berigo recommends

  • Push the update to all iPhone and iPad devices now, and confirm in your MDM that it actually installed.
  • Prioritise devices belonging to executives, board members and others with access to sensitive material.
  • Set a policy that blocks access to company data from devices several versions behind.
  • Consider Lockdown Mode for the few people who are realistic targets of directed attacks.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch