Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeTechnologyGoogle and Apple rush out emergency fixes after zero-day attacks hit targeted users

Google and Apple rush out emergency fixes after zero-day attacks hit targeted users

The companies confirmed that at least some attacks were already underway before patches were prepared, suggesting that a government-backed actor or a commercial spyware vendor may be involved.

December 14, 2025 / 11:52 IST
Security update

Google and Apple have issued emergency security updates this week after uncovering a sophisticated hacking campaign that exploited previously unknown vulnerabilities in their products. The companies confirmed that at least some attacks were already underway before patches were prepared, suggesting that a government-backed actor or a commercial spyware vendor may be involved.

Google moved first on Wednesday, pushing out fixes for several Chrome flaws. One of the vulnerabilities was already being used in active attacks, but the company initially withheld all technical details. By Friday, Google quietly updated its advisory to credit the discovery to Apple’s own security engineering team alongside Google’s Threat Analysis Group, the unit that tracks state hacking operations and spyware firms. That collaboration is rare and indicates the campaign was serious enough to prompt cross-company coordination.

Hours later, Apple rolled out its own emergency updates across nearly its entire product line, including iPhone, iPad, Mac, Vision Pro, Apple Watch, Apple TV and Safari. The company confirmed that two iOS vulnerabilities had been exploited in what it called an “extremely sophisticated attack against specific targeted individuals” on devices running software versions older than iOS 26. Apple typically uses that phrasing to signal real-world exploitation by advanced actors, often involving government surveillance teams or high-end spyware providers such as NSO Group or Paragon Solutions.

Zero-day attacks remain among the most dangerous threats because they take advantage of security flaws that vendors have not yet discovered or patched. These exploits are frequently used against journalists, activists, political figures and others who might be of interest to state-sponsored groups.

Neither company has disclosed who was targeted or how many users were affected, and both declined to comment on the ongoing investigation. However, the simultaneous emergency responses from Apple and Google point to a coordinated threat actor capable of breaching multiple platforms with tailored exploits.

Users are strongly urged to update their devices immediately.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Ayush Mukherjee
first published: Dec 14, 2025 11:52 am

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347