惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
月光博客
月光博客
B
Blog
罗磊的独立博客
GbyAI
GbyAI
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
The GitHub Blog
The GitHub Blog
人人都是产品经理
人人都是产品经理
博客园 - Franky
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
Visual Studio Blog
MyScale Blog
MyScale Blog
Google DeepMind News
Google DeepMind News
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Ransomware scum, other crims exploit 4 old Microsoft bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day
Apple, Google forced to issue emergency 0-day patches
Carly Page Carly Page · 2025-12-15 · via The Register - Security: Patches

Patches

Both admit attackers were already exploiting the bugs, with scant detail and hints of spyware-grade abuse

Apple and Google have both issued emergency patches after zero-day bugs were caught being actively exploited in what the companies describe as "sophisticated" real-world attacks.

Over the past few days, the two tech giants have rushed updates out the door to close vulnerabilities that attackers were already abusing against an unspecified number of targets, once again forcing users to patch first and ask questions later.

Apple pushed fresh security updates across much of its ecosystem, including iPhones, iPads, and Macs, fixing a pair of bugs in WebKit that it says may have been abused in an "extremely sophisticated attack against specific targeted individuals." As usual, Cupertino was light on technical detail, offering little more than a warning that the exploits were real and already in circulation.

Google, meanwhile, shipped a Chrome Stable channel update addressing multiple security flaws, including at least one zero-day that had already been exploited before a fix was available. The high-risk bug, tracked as CVE-2025-14174, was described as an out-of-bounds memory access vulnerability, with Google acknowledging it was aware of an exploit in the wild.

Google quietly fixed the Chrome bug last Wednesday, but said the vulnerability was still "under coordination." The Chocolate Factory updated its patch notes after Apple disclosed its own findings, revealing the overlap between the two companies' investigations.

Neither company has spilled many technical details, but Google credits the discovery of CVE-2025-14174 to Apple's security engineering team and Google's Threat Analysis Group – a unit better known for tracking mercenary spyware vendors and state-backed intrusion campaigns than for chasing everyday malware. That attribution strongly hints this was spyware-grade exploitation rather than opportunistic drive-by hacking.

The flurry of fixes adds to a growing zero-day tally for both firms. With these latest updates, Apple has now patched nine vulnerabilities exploited in the wild so far in 2025, while Google has been forced to tackle eight Chrome zero-days this year, a pace that suggests attackers continue to prize browsers and mobile platforms as some of the most lucrative real estate around. ®