Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Japanese devs face font licensing dilemma as leading provider increases annual plan price from $380 to $20,000+

    Indie dev Chequered Ink puts together $10 10,000 game assets pack so developers “don’t feel the need to turn to AI”

    Valorant Mobile is China’s biggest mobile launch of 2025 | News-in-Brief

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      Five Cryptocurrencies That Often Rally Around Christmas

      December 3, 2025

      Why Trump-Backed Mining Company Struggles Despite Bitcoin’s Recovery

      December 3, 2025

      XRP ETFs Extend 11-Day Inflow Streak as $1 Billion Mark Nears

      December 3, 2025

      Why AI-Driven Crypto Exploits Are More Dangerous Than Ever Before

      December 3, 2025

      Bitcoin Is Recovering, But Can It Drop Below $80,000 Again?

      December 3, 2025
    • Technology

      Criteo CEO Michael Komasinski on agentic commerce, experiments with LLMs, and M&A rumors

      December 3, 2025

      Future of TV Briefing: The streaming ad upfront trends, programmatic priorities revealed in Q3 2025 earnings reports

      December 3, 2025

      Omnicom’s reshuffled leadership emerges as the ad industry’s new power players

      December 3, 2025

      OpenX redraws the SSP-agency relationship

      December 3, 2025

      TikTok Shop sheds bargain-bin reputation as average prices climb across categories

      December 3, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»iPhone, iPad update fixes critical WebKit flaw
    Technology

    iPhone, iPad update fixes critical WebKit flaw

    TechAiVerseBy TechAiVerseMarch 12, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    iPhone, iPad update fixes critical WebKit flaw
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    iPhone, iPad update fixes critical WebKit flaw

    hanohiki – stock.adobe.com

    iPhone and iPad users are advised to update their devices as Apple addresses an out-of-bounds write issue in the WebKit browser engine that appears to have been exploited in targeted cyber attacks

    By

    • Alex Scroxton,
      Security Editor

    Published: 12 Mar 2025 12:35

    Apple has released updated versions of its iOS and iPadOS mobile operating system (OS) that address a potentially dangerous vulnerability that appears to have been exploited in the wild.

    The two releases, iOS 18.3.2 and iPadOS 18.3.2, are available for iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later.

    Collectively, the update addresses a single vulnerability tracked as CVE-2025-24201. Apple customarily releases very sparse details of the vulnerabilities it addresses to avoid giving too much away to threat actors, and the flaw in question is no exception.

    Apple revealed that the flaw is an out-of-bounds write issue affecting the WebKit open source web browser engine that powers Safari, Mail, App Store and many other Apple and Linux ecosystem applications.

    Cupertino said: “Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2.”

    Version 17.2 of the two OSes dates back just over a year to December 2023, and besides security fixes brought a large number of new features to Apple’s mobile estate, including the launch of a diary feature called Journal, and enhancements to its Weather app, among other things.

    Nation-state adversary?

    In its update notes, Apple indicated that it took steps to address the issue after it became aware of exploitation of CVE-2025-24201 in the wild. The firm said: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.”

    The fact that this attack is being described as sophisticated and targeted likely indicates that the vulnerability was used by a nation-state threat actor, possibly against individuals of interest to the intelligence services in that country. To Western ears, this could indicate exploitation by actors linked to China, Iran, North Korea or Russia.

    However, given Apple mobile devices are so widely used, other countries and even private companies are known to seek out and leverage vulnerabilities in its device estate for similar purposes.

    Notably, disgraced Israeli spyware manufacturer NSO Group – the organisation behind the Pegasus malware that was famously used by the Saudi Arabian regime against murdered journalist Jamal Khashoggi – exploited multiple Apple vulnerabilities in the service of its mercenary activities.

    Even though this might indicate the risk to everyday members of the public might be limited, Sylvain Cortes, vice-president of strategy at Hackuity, told Computer Weekly that all users should take steps to protect themselves.

    “The flaw poses a significant risk to users of older versions of the operating system, particularly those released before iOS 17.2,” said Cortes. “We highly encourage users to update their devices to iOS 18.3.2 as soon as possible to maintain the security and privacy of their data.”

    Besides the fix, the update also brings new customisation options for Apple users, a redesigned Photos application, “new ways to express yourself” in Messages, a hiking feature in Maps, and updates to Wallet.

    Read more on Application security and coding requirements


    • Apple zero day used in ‘extremely sophisticated attack’

      By: Alexander Culafi


    • Apple zero-day vulnerability under attack on iOS devices

      By: Rob Wright


    • Apple discloses 2 iOS zero-day vulnerabilities

      By: Alexander Culafi


    • Apple patches zero-days amid ‘foundational’ post-quantum update

      By: Alex Scroxton

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleOur data, our decisions, our AI future: why we need an AI Regulation Bill
    Next Article Acclaim relaunches, led by CEO Alex Josef
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Criteo CEO Michael Komasinski on agentic commerce, experiments with LLMs, and M&A rumors

    December 3, 2025

    Future of TV Briefing: The streaming ad upfront trends, programmatic priorities revealed in Q3 2025 earnings reports

    December 3, 2025

    Omnicom’s reshuffled leadership emerges as the ad industry’s new power players

    December 3, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025467 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025159 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202584 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202563 Views
    Don't Miss
    Gaming December 3, 2025

    Japanese devs face font licensing dilemma as leading provider increases annual plan price from $380 to $20,000+

    Japanese devs face font licensing dilemma as leading provider increases annual plan price from $380…

    Indie dev Chequered Ink puts together $10 10,000 game assets pack so developers “don’t feel the need to turn to AI”

    Valorant Mobile is China’s biggest mobile launch of 2025 | News-in-Brief

    Epic Games Store decides “at the last minute” not to distribute Horses

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Japanese devs face font licensing dilemma as leading provider increases annual plan price from $380 to $20,000+

    December 3, 20250 Views

    Indie dev Chequered Ink puts together $10 10,000 game assets pack so developers “don’t feel the need to turn to AI”

    December 3, 20250 Views

    Valorant Mobile is China’s biggest mobile launch of 2025 | News-in-Brief

    December 3, 20250 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.