Apple and Google Quietly Close Critical WebKit Zero-Days Linked to Sophisticated Targeted Attacks + Video

Listen to this Post

Featured Image

Introduction

Apple’s latest security updates arrived without spectacle, yet the implications are anything but ordinary. Beneath the routine language of patch notes lies evidence of highly targeted exploitation, cross-vendor coordination, and vulnerabilities powerful enough to concern both Apple and Google at the same time. Two zero-day flaws inside WebKit, Apple’s browser engine, were patched amid warnings of “extremely sophisticated attacks,” a phrase the company reserves for some of the most serious threat activity in its ecosystem. The restrained disclosure strategy has only intensified questions about who was targeted, how the exploits worked, and why details remain scarce.

the Original Report

Apple disclosed and patched two zero-day vulnerabilities affecting WebKit, its open source browser engine used across Safari and iOS applications. The first flaw, tracked as CVE-2025-43529, involved a use-after-free condition that could allow attackers to execute arbitrary code by processing maliciously crafted web content. Apple mitigated the issue through improved memory management. The second vulnerability, CVE-2025-14174, was described as a memory corruption flaw triggered in a similar way, addressed through enhanced validation.

Both vulnerabilities were discovered in collaboration with Google’s Threat Analysis Group, highlighting a rare but important alignment between the two companies. Apple released fixes for these issues on December 12 through iOS 26.2, iPadOS 26.2, iOS 18.7.3, iPadOS 18.7.3, and macOS Tahoe 26.2. What drew particular attention was Apple’s acknowledgment that these flaws “may have been exploited in an extremely sophisticated attack against specific targeted individuals” running older versions of iOS.

Apple did not elaborate on the nature of the attacks, the identities of the targets, or the threat actors involved. This language echoes previous advisories associated with commercial spyware campaigns. In September, Apple issued direct notifications to users targeted by spyware, coinciding with the disclosure of another zero-day, CVE-2025-43300, used in similarly described attacks.

The mystery deepened when Google revealed that a Chrome zero-day it patched the previous week was actually CVE-2025-14174, the same vulnerability Apple had fixed in WebKit. Google described it as an out-of-bounds memory access issue in ANGLE, its graphics abstraction layer. The bug was reportedly discovered by Apple’s Security Engineering and Architecture team alongside Google’s Threat Analysis Group.

Both Apple and Google have declined to provide further technical details. Security experts suggest this silence is intentional. Andy Piazza of Palo Alto Networks noted that detailed patch disclosures can act as blueprints for attackers, creating a race between defenders deploying updates and adversaries reverse-engineering fixes. Rapid7’s Douglas McKee added that the coordinated, minimal disclosure indicates the vulnerabilities were considered high-risk and potentially already known to advanced threat actors, particularly because memory safety flaws in shared graphics components are valuable, cross-platform, and easily chained in complex exploits.

What Undercode Say:

The most striking aspect of this incident is not just the vulnerabilities themselves, but the behavior of the vendors involved. Apple and Google rarely move in lockstep unless the stakes are unusually high. When a WebKit flaw maps directly onto a Chrome and ANGLE vulnerability, it signals shared architectural risk across modern browsers and graphics pipelines.

WebKit remains one of the most attractive targets for high-end attackers because it sits at the intersection of web content, device privileges, and user trust. A successful exploit can turn a simple webpage into a silent delivery mechanism for surveillance or compromise. Memory corruption and use-after-free bugs are especially prized because they bypass multiple layers of modern security when chained correctly.

Apple’s repeated use of the phrase “extremely sophisticated attack” is not casual language. Historically, it has aligned with activity from commercial spyware vendors or state-linked operators targeting journalists, activists, diplomats, or political figures. The absence of attribution does not reduce the severity; it reinforces the likelihood that the attacks are ongoing, sensitive, or legally complex.

Google’s involvement adds another dimension. The fact that Apple’s security team helped identify a Chrome-related vulnerability suggests deep intelligence sharing behind the scenes. This is not routine vulnerability research; it is coordinated damage control. When vendors choose silence over transparency, it often means exploitation was already observed in the wild and disclosure could accelerate copycat attacks.

The ANGLE connection is particularly concerning. Graphics abstraction layers are deeply embedded, broadly shared, and notoriously difficult to secure. A flaw there is not confined to one browser or operating system. It can ripple across platforms, devices, and vendors, making it ideal for long-term exploitation campaigns.

This episode also highlights a growing asymmetry in cybersecurity. Users are urged to update immediately, yet are given almost no context about why. Meanwhile, advanced attackers operate with patience, resources, and intimate knowledge of platform internals. The quiet patching strategy protects the ecosystem in the short term, but it leaves defenders and researchers largely in the dark.

Ultimately, this is less about two CVEs and more about a pattern. Browser engines are becoming the primary battlefield for high-end cyber operations. As long as web content remains a universal interface, WebKit and its peers will continue to attract the most capable adversaries in the world.

Fact Checker Results

✅ Apple confirmed both WebKit vulnerabilities were exploited in highly targeted, sophisticated attacks.
✅ Google acknowledged CVE-2025-14174 as a Chrome zero-day linked to ANGLE and coordinated with Apple.
❌ No public technical exploit details or attacker attribution have been disclosed by either vendor.

Prediction

📊 Apple and Google will continue coordinated, low-detail disclosures for high-risk zero-days as spyware threats grow.
📊 WebKit and shared graphics components will remain prime targets for advanced exploitation chains.
📊 User-level threat notifications and silent patching will become more common than full public transparency.

▶️ Related Video (82% Match):

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon