Apple iOS 26.2 Update Fixes Zero-Day Security Issues

Apple iOS 26.2 Update Fixes Zero-Day Security Issues

Apple Releases iOS 26.2 and iPadOS 26.2 with Critical Security Fixes, Including Two Zero-Days

Apple has rolled out iOS 26.2 and iPadOS 26.2, addressing a broad set of security vulnerabilities—including two zero-day flaws actively exploited in targeted attacks against iOS users.

The update resolves at least 30 vulnerabilities across core components, from the kernel to WebKit, underscoring the intensity of ongoing probing by threat actors within Apple’s ecosystem.

Two Actively Exploited Zero-Days

The most critical fixes involve CVE-2025-43529 and CVE-2025-14174, both in WebKit, the engine powering Safari and numerous iOS apps. Apple reports these bugs were likely exploited via malicious web content in highly targeted attacks.

  • CVE-2025-14174: A memory corruption flaw in ANGLE (Almost Native Graphics Layer Engine), used for WebGL rendering. Initially discovered in Chrome and patched on December 11, 2025, this vulnerability was actively exploited before mitigation.
  • CVE-2025-43529: A use-after-free issue in WebKit, potentially enabling arbitrary code execution. Apple confirmed its impact extended to iOS through shared dependencies.

Both vulnerabilities were uncovered by Google’s Threat Analysis Group (TAG) in collaboration with Apple’s internal security teams. Technical details remain limited due to responsible disclosure practices, but Apple notes exploitation was confined to pre-iOS 26 devices, suggesting earlier updates mitigated some attack vectors.

Additional High-Risk Fixes

Beyond the zero-days, iOS 26.2 addresses several significant flaws:

  • CVE-2025-46285 (Kernel): Integer overflow enabling local privilege escalation to root.
  • CVE-2025-46288 (App Store): Improper permission checks allowing apps to access Apple Pay tokens.
  • CVE-2025-43428 (Photos): Unauthorized access to hidden photos.
  • CVE-2025-43542 (FaceTime): Screen-sharing sessions could inadvertently expose password fields.
  • CVE-2025-46276 & CVE-2025-46292: Unauthorized data access via Messages and Telephony framework.

The update also includes multiple WebKit fixes for type confusion, buffer overflows, use-after-free bugs, and race conditions—issues that could lead to arbitrary code execution simply by visiting malicious websites. These were reported by researchers from Trend Micro ZDI, Epic Games, and Google’s Big Sleep team.

Update Now

Apple strongly advises all iPhone and iPad users to install iOS 26.2 and iPadOS 26.2 immediately via: Settings → General → Software Update → Download and Install iOS 26.2

Related Posts
Leave a Reply

Your email address will not be published.Required fields are marked *