ENISA EUVD · EUVD-2025-203963Known-exploited evidence recordedA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 was also issued in response to this report.
Official EUVD recordBSI · German · WID-SEC-W-2025-2838Apple macOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, um Sicherheitsvorkehrungen zu umgehen, und um beliebigen Programmcode auszuführen.
Official advisoryBSI · German · WID-SEC-W-2026-0402Apple iOS und iPadOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Apple iOS und Apple iPadOS ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.
Official advisoryBSI · German · WID-SEC-W-2026-0403Apple macOS Tahoe, Sequoia und Sonoma: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Apple macOS ausnutzen, um Administratorrechte zu erlangen, beliebigen Code auszuführen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.
Official advisoryBSI · German · WID-SEC-W-2025-2891WebKitGTK: Mehrere Schwachstellen ermöglichen Codeausführung und DoSEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in WebKitGTK ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial-of-Service-Zustand zu verursachen.
Official advisoryBSI · German · WID-SEC-W-2025-2836Apple iOS und iPadOS: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Apple iOS und Apple iPadOS ausnutzen, um sich erhöhte Berechtigungen zu verschaffen – inklusive Root-Rechten –, um Denial-of-Service-Angriffe oder Speicherbeschädigungen durchzuführen, um Spoofing-Angriffe durchzuführen, um Informationen offenzulegen, um beliebigen Code auszuführen oder um andere, nicht näher spezifizierte Angriffe durchzuführen.
Official advisoryBSI · German · WID-SEC-W-2025-2837Apple Safari: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Apple Safari ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Speicherbeschädigungen durchzuführen und andere, nicht spezifizierte Angriffe durchzuführen.
Official advisoryCERT-FR · French · CERTFR-2026-AVI-0158Multiples vulnérabilités dans les produits Applee 126352 du 11 février 2026
https://support.apple.com/en-us/126352
Bulletin de sécurité Apple 126353 du 11 février 2026
https://support.apple.com/en-us/126353
Bulletin de sécurité Apple 126354 du 11 février 2026
https://support.apple.com/en-us/126354
Référence CVE CVE-2025-14174
https://www.cve.org/CVERecord?id=CVE-2025-14174
Référence CVE CVE-2025-43338
https://www.cve.org/CVERecord?id=CVE-2025-43338
Référence CVE CVE-2025-43402
https://www.cve.org/CVERecord?id=CVE-2025-43402
Référence CVE CVE-2025-43403
https://www.cve.org/CVERecord?id=CVE-2025-43403
Référence CVE CVE-2025-43417
https://www.cve.org/CVERecord?id=CVE-2025-43417
Référence CVE CVE-2025-43529
https://www.cve.org/CVERecord?id=CVE-2025-43529
Référence CVE CVE-2025-43533
https://www.cve.org/CVERecord?id=CVE-2025-43533
Référence CVE CVE-2025-43537
https://www.cve.org/CVERecord?id=CVE-2025-43537
Référence CVE CVE-2025-46283
https://www.cve.org/CVERecord?id=CVE-2025-46283
Référence CVE CVE-2025-46290
https://www.cve.org/CVERecord?id=CVE-2025-46290
Référence CVE CVE-2025-46300
https://www.cve.org/CVERecord?id=CVE-2025-46300
Référence CVE CVE-2025-46301
https://www.cve.org/CVERecord?id=CVE-2025-46301
Référence CVE CVE-2025-46302
https://www.cve.org/CVERecord?id=CVE-2025-46302
Référence CVE CVE-2025-46303
https://www.cve.org/CVERecord?id=
Official advisoryCERT-FR · French · CERTFR-2025-AVI-1110Multiples vulnérabilités dans les produits Appleversions 18.7.x antérieures à 18.7.3
iPadOS versions 26.x antérieures à 26.2
macOS Sequoia versions antérieures à 15.7.3
macOS Sonoma versions antérieures à 14.8.3
macOS Tahoe versions antérieures à 26.2
Safari versions antérieures à 26.2
tvOS versions antérieures à 26.2
visionOS versions antérieures à 26.2
watchOS versions antérieures à 26.2
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Apple indique que les vulnérabilités CVE-2025-14174 et CVE-2025-43529 sont activement exploitées.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
Bulletin de sécurité Apple 125884 du 12 décembre 2025
https://support.apple.com/en-us/125884
Bulletin de sécurité Apple 125885 du 12 décembre 2025
https://support.apple.com/en-us/125885
Bulletin de sécurité Apple 125886 du 12 décembre 2025
https://support.apple.com/en-us/125886
Bulletin de sécurité Apple 125887 du 12 décembre 2025
https://support.apple.com/en-us/125887
Bulletin de sécurité Apple 125888 du 12 décembre 2025
https://support.apple.com/en-us/125888
Bulletin de sécurité Ap
Official advisoryNBSZ-NKI · Hungarian · cve-2025-43529CVE-2025-43529Magas
Official advisoryNCSC-NL · Dutch · NCSC-2025-0397Kwetsbaarheden verholpen in Apple iOS en iPadOSRecent updates addressed a use-after-free vulnerability and a memory corruption issue by enhancing memory management and implementing improved validation measures.
Official advisoryNCSC-NL · Dutch · NCSC-2025-0396Kwetsbaarheden verholpen in Apple macOSRecent updates addressed a use-after-free vulnerability and a memory corruption issue by enhancing memory management and implementing improved validation measures.
Official advisoryNCSC-NL · Dutch · NCSC-2026-0064Kwetsbaarheden verholpen in Apple iOS en iPadOSThe webkit2gtk3 update to version 2.50.4 addresses multiple security vulnerabilities, including use-after-free and memory corruption issues, potentially allowing arbitrary code execution through malicious web content.
Official advisoryNCSC-NL · Dutch · NCSC-2026-0063Kwetsbaarheden verholpen in Apple macOSThe webkit2gtk3 update to version 2.50.4 addresses multiple security vulnerabilities, including use-after-free and memory corruption issues, potentially allowing arbitrary code execution through malicious web content.
Official advisory