Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

28 September 2026
How a Gen Zer built a .7 billion defense tech startup backed by Sequoia

How a Gen Zer built a $3.7 billion defense tech startup backed by Sequoia

28 September 2026
Fraud And The Economics Of Fear

Fraud And The Economics Of Fear

28 September 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Apple Confirms iPhone Attacks—All Users Must Update Now
Innovation

Apple Confirms iPhone Attacks—All Users Must Update Now

Press RoomBy Press Room13 December 20255 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Apple Confirms iPhone Attacks—All Users Must Update Now

Updated on Dec. 13 with additional analysis of the new attack warning.

Apple has just warned that two iPhone vulnerabilities “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” It follows this month’s spyware warnings, issued to iPhone users around the world.

Both vulnerabilities have now been fixed in iOS 26.2, released today. But while the update now message applies to users already running iOS 26, there’s a more serious warning for those yet to upgrade. These attacks targeted individuals “on versions of iOS before iOS 26.” And even though iOS 18 is still being patched, it’s not worth the risk.

Apple wants you to upgrade. You should do exactly that.Apple has disclosed that the two vulnerabilities are linked. CVE-2025-14174 and CVE-2025-43529 were both “issued in response to this report.” One is attributed to Google’s Threat Analysis Group, the other to Google’s threat hunters and Apple itself.

And both affect WebKit. One, Apple says, risks a browser “processing maliciously crafted web content (that) may lead to arbitrary code execution.” While the other “may lead to memory corruption.” This has the hallmarks of a chained spyware attack.

According to Ali Mousavifar from Menlo Security, “the two active WebKit exploits in iOS 26.2 highlight a clear trend: browser engines are a primary target for attackers. We should expect these types of attacks to continue as the browser becomes the center of modern work. Relying solely on patching is a reactive game.”

“In all probability, these vulnerabilities have been chained to achieve exploitation,” Mayuresh Dani from Qualys told me. “WebKit has a well-documented history of serving as the primary entry point for sophisticated spyware and surveillance campaigns.” That includes “now infamous monitoring spywares such as Pegasus, which have consistently relied on WebKit vulnerabilities as its primary attack vector.”

Dani says iPhone users must “follow operational security practices, such as updating to iOS 26.2 immediately, using iCloud Private Relay to mask their IP and encrypt DNS queries (and) also as a practice, users should enable private browsing and disable JavaScript temporarily while interacting with untrusted sites.”

The two exploited vulnerabilities are amongst eight WebKit threats patched in this release. Others are various types of memory mishandling, which opens the door to destabilizing an app or the OS, potentially allowing other types of exploits to be used. Again, just more reasons to ensure you install the update as soon as it shows available.

We have seen WebKit zero-day attacks before. It’s a prime target for spyware developers building and marketing exploits. These latest vulnerabilities can be added to the “17 zero-day bugs in WebKit that attackers have exploited in the wild” since 2023. And while these are targeted at very specific individuals, vulnerabilities have a nasty habit of getting into the wild and spreading further down the food chain.

“Users should urgently update all their impacted Apple devices,” James Maude from BeyondTrust warns. “Even though this only appears to be linked to a small number of targeted attacks it will quickly become a must have exploit for a range of threat actors.”

There is a further risk to users beyond the two exploited vulnerabilities, now that iOS 26’s fixes are in the public domain. For example, “an app may be able to access sensitive user data” in Messages or “password fields may be unintentionally revealed when remotely controlling a device over FaceTime.”

At the beginning of December, Google also warned that its OS was under attack. Again it was two vulnerabilities that were being exploited in the wild to target Android users. It rushed out an emergency update within hours and Pixels were patched within days.

Dani explains “the two critical WebKit vulnerabilities are memory safety violations that Apple confirms were weaponized in real-world targeted attacks against specific individuals on pre-iOS 26 devices. CVE-2025-43529 allows threat actors a direct code execution capability, while CVE-2025-14174 provides the much needed sandbox escape and privilege escalation capabilities which makes it devastating.”

The other notable vulnerability beyond WebKit, per Cyber Press, is “ a critical Kernel issue (CVE-2025-46285) in which a malicious app could gain root privileges due to an integer overflow bug. The fix involves adopting 64-bit timestamps to prevent privilege escalation exploits. Another serious flaw in the App Store (CVE-2025-46288) could have allowed apps to access sensitive payment tokens, exposing financial data; this issue is now fixed with stricter permission controls.”

Maude warns “WebKit is the underpinning for every iOS browser and many apps as Apple requires it to be used for apps in their store. Every browser uses the same WebKit rendering engine layering additional functionality layer on top . While this allows them to control the ecosystem, it also creates an inherent point of failure. If Webkit is vulnerable your entire device could be vulnerable when viewing content online.”

This isn’t the first time we’ve seen Android and iPhone attacks disclosed and addressed the same month. Both operating systems are being attacked by the same mercenary spyware industry, so it should be no surprise. Both Apple and Google have done a good job in rushing out fixes to everyone, everywhere. The caveat on the Android side is that this only works for Pixels. Other OEMs — Samsung for example — cannot do the same.

America’s cyber defense agency issued its own warning following the Android release. We can almost certainly expect the same for Apple users by the beginning of next week.

“There’s no workaround or user behavior that meaningfully mitigates this risk,” says Keeper Security’s Darren Guccione. Installing the update “is the only effective defense. Once patches are public, the exposure window widens for anyone who delays updating.”

Apple attack apple update now warning ios 26 vs ios 18 ios 26.2 iPhone spyware attack iphone update warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

28 September 2026
Fraud And The Economics Of Fear

Fraud And The Economics Of Fear

28 September 2026
The Future Of Behavioral Healthcare Demands Continuous, Connected Care

The Future Of Behavioral Healthcare Demands Continuous, Connected Care

28 September 2026
Why Risk Mitigation Tools Are A Hard Sell In Pharma—And What Might Change That

Why Risk Mitigation Tools Are A Hard Sell In Pharma—And What Might Change That

26 September 2026
Lessons From Deploying At Fortune 50 Scale

Lessons From Deploying At Fortune 50 Scale

25 September 2026

Siegel Named MIT Schwarzman College Of Computing Innovation Fellow

25 September 2026
Don't Miss
Trump’s Tariffs Will Make AI Data Centers More Expensive

Trump’s Tariffs Will Make AI Data Centers More Expensive

By Press Room4 April 2025

Donald Trump’s administration has gone all-in on AI: A day after his inauguration, the newly-elected…

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

27 December 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
The Future Of Behavioral Healthcare Demands Continuous, Connected Care

The Future Of Behavioral Healthcare Demands Continuous, Connected Care

28 September 20260 Views
Why the U.S.-China thaw is harder than it looks

Why the U.S.-China thaw is harder than it looks

28 September 20261 Views
Xi-Trump summit ends with few deals, but a managed decline of U.S.-China relations may be the point

Xi-Trump summit ends with few deals, but a managed decline of U.S.-China relations may be the point

28 September 20261 Views
Airbnb CEO Brian Chesky spends 3 hours a day recruiting—he tells managers who don’t like it to leave

Airbnb CEO Brian Chesky spends 3 hours a day recruiting—he tells managers who don’t like it to leave

28 September 20261 Views

Recent Posts

  • The Chip Industry’s Emergent Challenge: Tackling The Memory Wall
  • How a Gen Zer built a $3.7 billion defense tech startup backed by Sequoia
  • Fraud And The Economics Of Fear
  • Memo smearing Amodei circulated in White House before Anthropic CEO’s dinner with President Trump
  • The Future Of Behavioral Healthcare Demands Continuous, Connected Care

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

The Chip Industry’s Emergent Challenge: Tackling The Memory Wall

28 September 2026
How a Gen Zer built a .7 billion defense tech startup backed by Sequoia

How a Gen Zer built a $3.7 billion defense tech startup backed by Sequoia

28 September 2026
Fraud And The Economics Of Fear

Fraud And The Economics Of Fear

28 September 2026
Most Popular
Memo smearing Amodei circulated in White House before Anthropic CEO’s dinner with President Trump

Memo smearing Amodei circulated in White House before Anthropic CEO’s dinner with President Trump

28 September 20261 Views
The Future Of Behavioral Healthcare Demands Continuous, Connected Care

The Future Of Behavioral Healthcare Demands Continuous, Connected Care

28 September 20260 Views
Why the U.S.-China thaw is harder than it looks

Why the U.S.-China thaw is harder than it looks

28 September 20261 Views

Archives

  • September 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.