Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games

    Study shows gaming can reduce stress, even the violent kind

    Hackers show how they can fully control your 2020 Nissan Leaf remotely

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple sued by shareholders for allegedly overstating AI progress

      June 22, 2025

      How far will AI go to defend its own survival?

      June 2, 2025

      The internet thinks this video from Gaza is AI. Here’s how we proved it isn’t.

      May 30, 2025

      Nvidia CEO hails Trump’s plan to rescind some export curbs on AI chips to China

      May 22, 2025

      AI poses a bigger threat to women’s work, than men’s, report says

      May 21, 2025
    • Business

      Google links massive cloud outage to API management issue

      June 13, 2025

      The EU challenges Google and Cloudflare with its very own DNS resolver that can filter dangerous traffic

      June 11, 2025

      These two Ivanti bugs are allowing hackers to target cloud instances

      May 21, 2025

      How cloud and AI transform and improve customer experiences

      May 10, 2025

      Cookie-Bite attack PoC uses Chrome extension to steal session tokens

      April 22, 2025
    • Crypto

      On-Chain Data Shows the Real Story Behind Iran’s $90 Million Nobitex Hack

      June 26, 2025

      European Commission to Loosen MiCA Rules Despite ECB Warnings

      June 26, 2025

      Trump Family’s World Liberty Financial To Make WLFI Token Tradable

      June 26, 2025

      US Housing Giants To Consider Crypto In Mortgage Loan Assessments

      June 26, 2025

      Content Tokenization Could be the Next Biggest AI Trend – Here’s Why

      June 26, 2025
    • Technology

      Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games

      June 26, 2025

      Study shows gaming can reduce stress, even the violent kind

      June 26, 2025

      Hackers show how they can fully control your 2020 Nissan Leaf remotely

      June 26, 2025

      How PC makers exploited BIOS copyright strings to unlock trial software during the Windows 95 era

      June 26, 2025

      Which operating system was targeted by the first ever mobile phone virus?

      June 26, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Shop Now
    Tech AI Verse
    You are at:Home»Technology»iPhone, iPad update fixes critical WebKit flaw
    Technology

    iPhone, iPad update fixes critical WebKit flaw

    TechAiVerseBy TechAiVerseMarch 12, 2025No Comments4 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    iPhone, iPad update fixes critical WebKit flaw
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    iPhone, iPad update fixes critical WebKit flaw

    hanohiki – stock.adobe.com

    iPhone and iPad users are advised to update their devices as Apple addresses an out-of-bounds write issue in the WebKit browser engine that appears to have been exploited in targeted cyber attacks

    By

    • Alex Scroxton,
      Security Editor

    Published: 12 Mar 2025 12:35

    Apple has released updated versions of its iOS and iPadOS mobile operating system (OS) that address a potentially dangerous vulnerability that appears to have been exploited in the wild.

    The two releases, iOS 18.3.2 and iPadOS 18.3.2, are available for iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.

    Collectively, the update addresses a single vulnerability tracked as CVE-2025-24201. Apple customarily releases very sparse details of the vulnerabilities it addresses to avoid giving too much away to threat actors, and the flaw in question is no exception.

    Apple revealed that the flaw is an out-of-bounds write issue affecting the WebKit open source web browser engine that powers Safari, Mail, App Store and many other Apple and Linux ecosystem applications.

    Cupertino said: “Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2.”

    Version 17.2 of the two OSes dates back just over a year to December 2023, and besides security fixes brought a large number of new features to Apple’s mobile estate, including the launch of a diary feature called Journal, and enhancements to its Weather app, among other things.

    Nation-state adversary?

    In its update notes, Apple indicated that it took steps to address the issue after it became aware of exploitation of CVE-2025-24201 in the wild. The firm said: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.”

    The fact that this attack is being described as sophisticated and targeted likely indicates that the vulnerability was used by a nation-state threat actor, possibly against individuals of interest to the intelligence services in that country. To Western ears, this could indicate exploitation by actors linked to China, Iran, North Korea or Russia.

    However, given Apple mobile devices are so widely used, other countries and even private companies are known to seek out and leverage vulnerabilities in its device estate for similar purposes.

    Notably, disgraced Israeli spyware manufacturer NSO Group – the organisation behind the Pegasus malware that was famously used by the Saudi Arabian regime against murdered journalist Jamal Khashoggi – exploited multiple Apple vulnerabilities in the service of its mercenary activities.

    Even though this might indicate the risk to everyday members of the public might be limited, Sylvain Cortes, vice-president of strategy at Hackuity, told Computer Weekly that all users should take steps to protect themselves.

    “The flaw poses a significant risk to users of older versions of the operating system, particularly those released before iOS 17.2,” said Cortes. “We highly encourage users to update their devices to iOS 18.3.2 as soon as possible to maintain the security and privacy of their data.”

    Besides the fix, the update also brings new customisation options for Apple users, a redesigned Photos application, “new ways to express yourself” in Messages, a hiking feature in Maps, and updates to Wallet.

    Read more on Application security and coding requirements


    • Apple zero day used in ‘extremely sophisticated attack’

      By: Alexander Culafi


    • Apple zero-day vulnerability under attack on iOS devices

      By: Rob Wright


    • Apple discloses 2 iOS zero-day vulnerabilities

      By: Alexander Culafi


    • Apple patches zero-days amid ‘foundational’ post-quantum update

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleOur data, our decisions, our AI future: why we need an AI Regulation Bill
    Next Article Acclaim relaunches, led by CEO Alex Josef
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games

    June 26, 2025

    Study shows gaming can reduce stress, even the violent kind

    June 26, 2025

    Hackers show how they can fully control your 2020 Nissan Leaf remotely

    June 26, 2025
    Leave A Reply Cancel Reply

    Top Posts

    New Akira ransomware decryptor cracks encryptions keys using GPUs

    March 16, 202525 Views

    OpenAI details ChatGPT-o3, o4-mini, o4-mini-high usage limits

    April 19, 202522 Views

    Rsync replaced with openrsync on macOS Sequoia

    April 7, 202516 Views

    Arizona moves to ban AI use in reviewing medical claims

    March 12, 202511 Views
    Don't Miss
    Technology June 26, 2025

    Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games

    Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games…

    Study shows gaming can reduce stress, even the violent kind

    Hackers show how they can fully control your 2020 Nissan Leaf remotely

    How PC makers exploited BIOS copyright strings to unlock trial software during the Windows 95 era

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Nvidia DLSS 4 transformer model exits beta, set to bring improved graphics to more games

    June 26, 20250 Views

    Study shows gaming can reduce stress, even the violent kind

    June 26, 20250 Views

    Hackers show how they can fully control your 2020 Nissan Leaf remotely

    June 26, 20250 Views
    Most Popular

    Ethereum must hold $2,000 support or risk dropping to $1,850 – Here’s why

    March 12, 20250 Views

    Xiaomi 15 Ultra Officially Launched in China, Malaysia launch to follow after global event

    March 12, 20250 Views

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.