“Se trata de una vulnerabilidad presente en código de fuente abierta, y el software de Apple se encuentra entre los proyectos afectados”, informó la compañía.
Además, advirtió que la falla podría provocar cierres inesperados al procesar contenido web malicioso.
Versiones actualizadas
iOS 18.6 y iPadOS 18.6: iPhone XS y posteriores, iPad Pro (13”, 12.9” 3ra gen. y posteriores, 11” 1ra gen. y posteriores), iPad Air 3ra gen. y posteriores, iPad 7ma gen. y posteriores, y iPad mini 5ta gen. y posteriores.
- iPadOS 17.7.9: iPad Pro 12.9” 2da gen., iPad Pro 10.5”, y iPad 6ta gen.
- macOS Sequoia 15.6: para todos los equipos compatibles.
- tvOS 18.6: Apple TV HD y Apple TV 4K (todos los modelos).
- watchOS 11.6: Apple Watch Series 6 y posteriores.
- visionOS 2.6: Apple Vision Pro.
Recomendación: Aunque hasta el momento no se ha reportado ningún ataque específico contra usuarios de dispositivos Apple, se recomienda encarecidamente actualizar a la versión más reciente del software para mantener la seguridad y estabilidad del sistema.
Apple Fixes Safari Flaw Also Exploited as a Zero-Day in Google Chrome
Apple has rolled out security updates across its product ecosystem, including a key patch for a vulnerability previously exploited in Google Chrome as a zero-day earlier this month.
The flaw, cataloged as CVE-2025-6558 with a CVSS score of 8.8, stems from improper input validation in the browser’s ANGLE and GPU components. An attacker could leverage this issue through a specially crafted HTML page to break out of the browser’s sandbox protections.
Although specifics on the exploit remain undisclosed, Google acknowledged active exploitation in the wild. The vulnerability was reported by researchers Clément Lecigne and Vlad Stolyarov from Google’s Threat Analysis Group (TAG).
Apple has confirmed the same vulnerability impacts WebKit, the open-source engine used by Safari, and has patched the issue in its latest updates.
“This is a vulnerability in open-source code, and Apple’s software is among the impacted projects,” the company said.
If exploited, it could cause Safari to crash unexpectedly while handling malicious web content.
Affected and Updated Versions
- iOS 18.6 and iPadOS 18.6: iPhone XS and newer, iPad Pro (13”, 12.9” 3rd gen and newer, 11” 1st gen and newer), iPad Air 3rd gen and newer, iPad 7th gen and newer, iPad mini 5th gen and newer.
- iPadOS 17.7.9: iPad Pro 12.9” 2nd gen, iPad Pro 10.5”, iPad 6th gen.
- macOS Sequoia 15.6: All compatible Macs.
- tvOS 18.6: All Apple TV HD and 4K models.
- watchOS 11.6: Apple Watch Series 6 and above.
- visionOS 2.6: Apple Vision Pro.
Recommendation: There’s no evidence this flaw was exploited against Apple device users directly, but it’s strongly recommended to update all software to stay protected.