iOS 26.2 Fixes 25 Vulnerabilities, with Contributions from Google, ByteDance, and Alibaba Teams

Deep News
2025/12/13

Apple has released iOS 26.2, iPadOS 26.2, and macOS Tahoe 26.2, addressing a total of 25 security vulnerabilities. Users are strongly advised to update immediately.

Among the patched vulnerabilities, the most critical are CVE-2025-43529 and CVE-2025-14174, two WebKit flaws discovered by Google's Threat Analysis Group. Apple confirmed that hackers have exploited these vulnerabilities to launch highly sophisticated targeted attacks on older iOS versions. The update mitigates these risks by enhancing memory management and validation mechanisms, preventing malicious web content from triggering arbitrary code execution.

For the App Store, Apple implemented additional restrictions to resolve a permissions issue that allowed apps to access sensitive payment tokens. This vulnerability, labeled CVE-2025-46288, was reported by ByteDance's IES Red Team researchers floeki and Zhongcheng Li and has now been fixed.

Apple also addressed a severe kernel-level integer overflow vulnerability (CVE-2025-46285), which could have been exploited to crash systems or gain root access. The flaw was identified and reported by Alibaba Group's Kaitao Xie and Xiaolong Bai. Apple engineers resolved the issue by introducing 64-bit timestamp technology, eliminating the underlying security risk.

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10