Apple has released a serious warning for iPhone users since it was confirmed that two of its vulnerabilities are likely to have been used in targeted attacks on individuals. The disclosure comes after a spate of spyware warnings sent to iPhone users earlier this month. Both vulnerabilities have been corrected in iOS 26.2’s release, but Apple is urging those who haven’t updated yet to do so right away. The company has said that this attack impacted devices using iOS before iOS 26, and procrastinating on updating could mean a user is left vulnerable. Security researchers caution that when such vulnerabilities are made public, they typically spread far beyond their initial victims.

Two Linked Vulnerabilities Exploited in the Wild

Apple said the vulnerabilities are linked and were fixed after reports of active exploitation.

ALSO READ: How To Update Or Change Your Phone Number Linked To Google And Gmail Account

The flaws are tracked as:

- CVE-2025-14174

- CVE-2025-43529

Both issues are exploitable in WebKit, the browser engine that powers Safari and all third-party browsers on iOS. One of the flaws can be exploited by nefarious web content to execute arbitrary code, and another could lead to memory corruption. Together, they offer a powerful glimpse of what looks like a chained spyware attack — where one exploit helps open the door and another escalates access.

Why WebKit Is a Prime Target

Browser engines are increasingly being targeted by attackers, security experts say. WebKit in particular has a long track record of being targeted in high-profile surveillance efforts.

Spyware like Pegasus, the researchers point out, has made extensive use of WebKit for silently compromising devices in the past. Because every iOS web browser and many apps rely on WebKit, one vulnerability can leave open the entire system when users access web content.

Experts Warn Against Delaying the Update

Security specialists strongly advise users to update to iOS 26.2 immediately.

Experts recommend:

- Installing iOS 26.2 as soon as it appears

- Using iCloud Private Relay to mask IP addresses

- Practicing safe browsing habits, especially on untrusted sites

But many experts argue that user behavior can’t solve the problem on its own. After patches go public, attackers often reverse-engineer them, so delayed updates are particularly dangerous.

More Than Just Two Vulnerabilities Fixed

Two of the exploited vulnerabilities are included in a group of eight WebKit flaws that were patched with iOS 26.2. A number of them concern memory handling and could cause apps or the operating system to become unstable, perhaps allowing for other exploits.

Beyond WebKit, Apple also fixed:

- A critical kernel vulnerability that could allow malicious apps to gain root privileges

- An App Store flaw that could have exposed sensitive payment tokens

These fixes further underline the urgency of installing the update.

ALSO READ: Airtel Cuts Data Benefits On Unlimited 5G Add-On Packs: Revised Details Explained

A Broader Pattern Across Mobile Platforms

This isn’t an isolated incident. Earlier this month, Google also revealed two Android bugs being used in malicious software attacks that required emergency patches. Both iOS and Android are set upon by the same commercial spyware ecosystem, security experts say, so everyone needs to update quickly.

Final Thoughts

What’s obvious from Apple’s warning is this: postponing iOS updates is no longer a safe strategy. Although the attacks may have focused on a relatively narrow group, history suggests that weaponized exploits rarely remain confined for long. With WebKit at the heart of the iOS ecosystem, even casual browsing can pose as a risk on unpatched devices. At this point the only real solution is if you install iOS 26.2 which should be treated as a priority, not an option.”