ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-43433
+4 in the same advisory: …43431 …43429 …43434 …43430
The issue was addressed with improved memory handling.

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted web content may lead to memory corruption.

NVD description · AI analysis pending
8.8
group max
1%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2025-6965
Memory Corruption in SQLite < 3.50.2 Affecting Apple and Siemens Products

CVE-2025-6965 is a numeric handling flaw (CWE-197) in SQLite versions before 3.50.2 in which the number of aggregate terms in a query can exceed the number of available columns, resulting in memory corruption. An attacker triggers it by getting an application that embeds SQLite to execute crafted SQL: the vector is network-based and requires only low privileges, but with high attack complexity (CVSS 4.0 base 7.2), and successful corruption carries high integrity impact on the running process. Because SQLite is embedded in countless applications and operating systems, every deployment running SQLite older than 3.50.2 is affected, including Apple's iPhone OS, iPadOS, macOS, tvOS, visionOS and watchOS and Siemens' RUGGEDCOM CROSSBOW and SIDIS Prime, which bundle the library. The flaw is not on the CISA KEV list and no public proof-of-concept is known, but Google reported that its Big Sleep AI discovered the bug as hackers were preparing to exploit it, and EPSS assigns a 75.8% probability of exploitation within 30 days.

Do: Upgrade SQLite to version 3.50.2 or later in every bundled or embedded deployment, and apply the corresponding Apple OS and Siemens RUGGEDCOM CROSSBOW/SIDIS Prime updates as vendors publish fixed releases. Inventory which applications, devices and internet-facing services ship vulnerable SQLite and prioritize anything that processes untrusted SQL, given the very high EPSS score (75.8% within 30 days) and Google's report that attackers were preparing to exploit this bug. Where patching is delayed, review aggregate SQL queries for cases where aggregate terms exceed available columns as a triage measure.

7.276%
  • SQLite all versions before 3.50.2
  • Apple iPhone OS (iOS) versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • Apple iPadOS versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • +6 more
massbillions of devices worldwide (SQLite ships embedded in virtually every operating system, browser and application; Apple's active device base alone exceeds 1…
Full article474 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 04, 2025Artificial Intelligence / Vulnerability

Google's artificial intelligence (AI)-powered cybersecurity agent called Big Sleep has been credited by Apple for discovering as many as five different security flaws in the WebKit component used in its Safari web browser that, if successfully exploited, could result in a browser crash or memory corruption.

The list of vulnerabilities is as follows -

  • CVE-2025-43429 - A buffer overflow vulnerability that may lead to an unexpected process crash when processing maliciously crafted web content (addressed through improved bounds checking)
  • CVE-2025-43430 - An unspecified vulnerability that could result in an unexpected process crash when processing maliciously crafted web content (addressed through improved state management)
  • CVE-2025-43431 & CVE-2025-43433 - Two unspecified vulnerabilities that may lead to memory corruption when processing maliciously crafted web content (addressed through improved memory handling)
  • CVE-2025-43434 - A use-after-free vulnerability that may lead to an unexpected Safari crash when processing maliciously crafted web content (addressed through improved state management)

Patches for the shortcomings were released by Apple on Monday as part of iOS 26.1, iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, watchOS 26.1, visionOS 26.1, and Safari 26.1. The updates are available for the following devices and operating systems -

  • iOS 26.1 and iPadOS 26.1 - iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
  • 18.7.2 and iPadOS 18.7.2 - iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
  • macOS Tahoe 26.1 - Macs running macOS Tahoe
  • tvOS 26.1 - Apple TV 4K (2nd generation and later)
  • visionOS 26.1 - Apple Vision Pro (all models)
  • watchOS 26.1 - Apple Watch Series 6 and later
  • Safari 26.1 - Macs running macOS Sonoma and macOS Sequoia

Big Sleep, formerly called Project Naptime, is an AI agent launched by Google last year as part of a collaboration between DeepMind and Google Project Zero to enable automated vulnerability discovery.

Earlier this year, Google said the large language model (LLM)-assisted framework identified a security flaw in SQLite (CVE-2025-6965, CVSS score: 7.2) that it said was at "risk of being exploited" by malicious actors.

While none of the vulnerabilities listed in Monday's security bulletins have been flagged as exploited in the wild, it's always a good practice to keep devices updated to the latest version for optimal protection.

(The story was updated after publication on November 5, 2025, to reflect the release of patches for iOS 18.7.2 and iPadOS 18.7.2.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html