Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome – The Hacker News
Apple on Tuesday released security updates for its entire software portfolio, including a fix for a vulnerability that Google said was exploited as a zero-day in the Chrome web browser earlier this month.
The vulnerability, tracked as CVE-2025-6558 (CVSS score: 8.8), is an incorrect validation of untrusted input in the browser’s ANGLE and GPU components that could result in a sandbox escape via a crafted HTML page.
While there are no details on how the issue has been weaponized by threat actors, Google acknowledged that an “exploit for CVE-2025-6558 exists in the wild.” Clément Lecigne and Vlad Stolyarov of Google’s Threat Analysis Group (TAG) have been credited with discovering and reporting the shortcoming.
The iPhone maker, in its latest round of software updates, also included patches for CVE-2025-6558, stating the vulnerability impacts the WebKit browser engine that powers its Safari browser.
“This is a vulnerability in open-source code and Apple Software is among the affected projects,” the company said in an advisory, adding it could be exploited to result in an unexpected crash of Safari when processing maliciously crafted web content.
The bug has been addressed in the following versions –
While there is no evidence that the vulnerability has been used to target Apple device users, it’s always a good practice to update to the latest versions of the software for optimal protection.
“Pip install and pray” won’t cut it in 2025. Learn fast, practical ways to secure Python code.
We’ll unpack how leading teams are using AI, privacy-first design, and seamless logins to earn user trust and stay ahead in 2025.
Get the latest news, expert insights, exclusive resources, and strategies from industry leaders – all for free.