Apple Fixes Critical Safari Zero-Day Vulnerability Already Under Active Attack


# Apple Releases Critical Security Updates to Fix Zero-Day Vulnerability

Apple has issued comprehensive security updates across its entire software ecosystem to address a critical vulnerability that was actively exploited in Google Chrome earlier this month.

## The Vulnerability Details

The security flaw, designated CVE-2025-6558 with a high severity score of 8.8, stems from improper validation of untrusted input within browser components. This weakness could allow attackers to escape security sandboxes through specially crafted web pages.

Google’s Threat Analysis Group researchers Clément Lecigne and Vlad Stolyarov discovered the vulnerability and confirmed that “an exploit for CVE-2025-6558 exists in the wild,” though specific attack methods remain undisclosed.

## Impact on Apple Devices

The vulnerability affects Apple’s WebKit browser engine, which powers Safari across all Apple devices. When exploited, malicious web content could cause Safari to crash unexpectedly. Apple acknowledged that this open-source code vulnerability impacts multiple software projects, including their own systems.

## Updated Software Versions

Apple has released patches across all major platforms:

**Mobile Devices:**
– iOS 18.6 and iPadOS 18.6 (iPhone XS and later, recent iPad models)
– iPadOS 17.7.9 (older iPad Pro and iPad 6th generation)

**Desktop and Other Devices:**
– macOS Sequoia 15.6 (all compatible Macs)
– tvOS 18.6 (Apple TV HD and 4K models)
– watchOS 11.6 (Apple Watch Series 6 and newer)
– visionOS 2.6 (Apple Vision Pro)

## Security Recommendation

While there’s no evidence of attacks targeting Apple users specifically, security experts strongly recommend updating all devices immediately. These updates provide essential protection against potential exploitation of this actively used vulnerability.

Users should check their device settings and install the latest software versions to ensure optimal security protection.

Share This Article