CISA has listed a critical zero-day vulnerability affecting various Apple products in its Known Exploited Vulnerabilities catalog, indicating it is being actively exploited. CVE-2025-43529 is a severe use-after-free vulnerability in WebKit, Apple’s rendering engine, affecting millions of users on iOS, iPadOS, macOS, and other Apple platforms.
A use-after-free vulnerability (CWE-416) in WebKit can cause memory corruption when a user visits a malicious webpage. CISA confirmed that threat actors are exploiting this vulnerability, leading to its addition to the KEV catalog on December 15, 2025.
By infosecbulletin
/ Wednesday , June 24 2026
On Wednesday, OpenAI introduced its first special AI chip. This is aimed at growing from just consumer products to being...
Read More
By infosecbulletin
/ Wednesday , June 24 2026
Bajaj Auto said on Tuesday that a ransomware attack impacted its systems and its subsidiary, Bajaj Auto Technology Ltd (BATL)....
Read More
By infosecbulletin
/ Wednesday , June 24 2026
A serious SSRF flaw, called CVE-2026-20230, in Cisco Unified Communications Manager Server is now being used in attacks. Cisco put out...
Read More
By infosecbulletin
/ Tuesday , June 23 2026
LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
By infosecbulletin
/ Tuesday , June 23 2026
Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
By infosecbulletin
/ Tuesday , June 23 2026
A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
By infosecbulletin
/ Monday , June 22 2026
The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
By infosecbulletin
/ Monday , June 22 2026
Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
By infosecbulletin
/ Sunday , June 21 2026
AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
By infosecbulletin
/ Sunday , June 21 2026
Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
The vulnerability is a serious method for various attacks, such as remote code execution, unauthorized file access, and moving through compromised systems.
Organizations must respond to this threat by January 5, 2026, based on the 21-day remediation period set by CISA’s guidance.
The vulnerability is not yet linked to ransomware campaigns, but confirmed exploitation suggests that advanced threat actors could weaponize it.
CISA advises organizations to address this vulnerability by following the BOD 22-01 guidelines. They should promptly implement vendor-supplied mitigations and security patches as soon as Apple provides them.