hi_heige
26-02-13 14:14

补充个细节,可能导致错误理解 虽然CVE-2025-43529 CVE-2025-14174 在iOS26.2里更新 但是公告明确标注了:an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26

另外强调下“网传”==不可信~ 所以现在没有证据MIE受到影响

另外在最新的 iOS 26.3 更新 http://t.cn/AXtys6j1 修复了另外一个CVE-2026-20700 ,来自于上面CVE-2025-43529 CVE-2025-14174的攻击链

Impact: An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

发布于 美国