News: 0180794038

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple Patches Decade-Old IOS Zero-Day, Possibly Exploited By Commercial Spyware (securityweek.com)

(Sunday February 15, 2026 @03:34AM (EditorDavid) from the fixing-a-hole dept.)


This week Apple patched iOS and macOS against what it [1]called "an extremely sophisticated attack against specific targeted individuals."

[2] Security Week reports that the bugs "could be exploited for information exposure, denial-of-service (DoS), arbitrary file write, privilege escalation, network traffic interception, sandbox escape, and code execution."

> Tracked [3]as CVE-2026-20700 , the zero-day flaw is described as a memory corruption issue that could be exploited for arbitrary code execution... The tech giant also noted that the flaw's exploitation is linked to attacks involving CVE-2025-14174 and CVE-2025-43529, two zero-days [4]patched in WebKit in December 2025...

>

> The three zero-day bugs were identified by Apple's security team and Google's Threat Analysis Group and their descriptions suggest that they might have been exploited by commercial spyware vendors... Additional information is available on Apple's [5]security updates page.

Brian Milbier, deputy CISO at Huntress, [6]tells the Register that the dyld/WebKit patch "closes a door that has been unlocked for over a decade."

Thanks to Slashdot reader [7]wiredmikey for sharing the article.



[1] https://support.apple.com/en-us/126346

[2] https://www.securityweek.com/apple-patches-ios-zero-day-exploited-in-extremely-sophisticated-attack/

[3] https://support.apple.com/en-us/126346

[4] https://www.securityweek.com/apple-patches-two-zero-days-tied-to-mysterious-exploited-chrome-flaw/

[5] https://support.apple.com/en-us/126346

[6] https://www.theregister.com/2026/02/12/apple_ios_263/

[7] https://www.slashdot.org/~wiredmikey



So while the summary doesn't make this clear (Score:2)

by 93 Escort Wagon ( 326346 )

CVE-2025-14174 was a Chrome vulnerability, and (if the "over a decade" comment is accurate) Chrome has likely also been vulnerable all this time.

Which makes sense, given Chrome and Safari's original shared code base.

dynamic linker (Score:2)

by johnjones ( 14274 )

that's why they went all out for

https://security.apple.com/blog/memory-integrity-enforcement/

be nice if they actually helped others i.e. linux

google have done half of this before apple...

JJ

IOS vs iOS (Score:2)

by Unpopular Opinions ( 6836218 )

Case matters: IOS is the Cisco classic OS for its routers and switches, whereas iOS is the actual Apple OS name for iPhone devices.

Programming for money sucks... you have to deal with PHBs, 16 hour days,
and spending the night in your cubicle half of the time to avoid the
Commute From Hell...

I minored in Journalism, so I tried to switch into a job as an IT pundit.
You'd think they'd welcome a geek like me with open arms, but they
didn't. Ziff-Davis wouldn't even give me an interview. I was "too
qualified" they said. Apparently my technical acumen was too much for
their organization, which employs Jesse Berst and the ilk.

It gets worse. I tried to get an entry-level reporting job for a
local-yokel paper. After the interview they gave me a "skills test": I had
to compose an article using Microsoft Word 97. Since I've never touched a
Windows box, I had no clue how to use it. When I botched the test, the
personnel manager spouted, "Your resume said you were a computer
programmer. Obviously you're a liar. Get out of my office now!"

-- Excerpt from a horror story about geek discrimination during
the Geek Grok '99 telethon