Apple Quietly Patches a Dangerous Zero-Day Flaw in Older iPhones and iPads — And You Should Care

Apple released iOS 16.7.13 to patch an actively exploited WebKit zero-day vulnerability on older iPhones and iPads, including iPhone 8 and iPhone X. The flaw allows remote code execution via malicious web content, and Apple warns it has been used in sophisticated targeted attacks.
Apple Quietly Patches a Dangerous Zero-Day Flaw in Older iPhones and iPads — And You Should Care
Written by Victoria Mossi

Apple just pushed a security update to devices many people assumed the company had stopped worrying about. The patch, released on June 30, 2025, fixes a WebKit vulnerability that Apple says may have already been exploited in targeted, sophisticated attacks. If you’re still running an iPhone 8, an iPad Air 3rd generation, or anything else stuck on iOS or iPadOS 16, this one’s for you.

The vulnerability, tracked as CVE-2025-37899, resides in WebKit — the browser engine that powers Safari and, by Apple’s mandate, every other browser on iOS. According to Apple’s security advisory, the flaw involves a use-after-free condition triggered during the processing of maliciously crafted web content. In plain language: visiting the wrong website could give an attacker the ability to execute arbitrary code on your device. Apple addressed the issue with improved memory management.

The fix arrives as iOS 16.7.13 and iPadOS 16.7.13. It covers iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch (1st generation), among other models that can’t run iOS 17 or later. As Lifehacker reported, this update matters precisely because these devices remain in active use by millions of people worldwide — people who may not realize they’re running hardware with a known, actively exploited security hole.

A zero-day fix for legacy hardware. That’s not nothing.

The Scope of the Threat — and Why WebKit Vulnerabilities Hit Different

WebKit zero-days occupy a particular category of danger on Apple platforms. Unlike Android, where users can install Chrome, Firefox, or other browsers running their own rendering engines, Apple requires all iOS browsers to use WebKit under the hood. This means a single WebKit flaw doesn’t just affect Safari users. It affects every person who opens a link on an iPhone or iPad, regardless of which browser icon they tap.

CVE-2025-37899 is a use-after-free bug, a class of memory corruption vulnerability that security researchers consider among the most dangerous. When software continues to reference memory after it’s been freed, attackers can manipulate what occupies that memory space. The result: code execution, often with the privileges of the process that triggered the flaw. For WebKit, that process handles rendering web content — a task that touches nearly everything a user does online.

Apple’s advisory states the vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals.” The company has used this exact phrasing repeatedly in recent months, a pattern that security analysts associate with state-sponsored or mercenary spyware operations. Apple doesn’t elaborate further. It never does.

But the pattern is telling. In January 2025, Apple patched CVE-2025-24085, a Core Media zero-day with identical language about sophisticated targeting. Earlier this year, the company also addressed CVE-2025-24200, a USB Restricted Mode bypass that Citizen Lab at the University of Toronto linked to targeted surveillance. And in March, Apple fixed CVE-2025-24201, another WebKit zero-day — one that Apple described as a supplementary fix for an attack blocked in iOS 17.2.

The cadence is accelerating.

What makes CVE-2025-37899 different is its reach backward. Apple typically issues these emergency patches for its current operating systems first and then, sometimes weeks later, backports them to older versions. This time, the company released the legacy patch relatively quickly. The same vulnerability was addressed in iOS 18.4.1 and macOS Sequoia updates earlier, meaning users on newer hardware should already be protected — assuming they’ve updated.

For users on older devices, the calculus is different. These are phones and tablets that Apple no longer sells, no longer features in marketing, and no longer supports with major OS upgrades. Yet the company continues to issue targeted security patches for them, a practice that reflects both the scale of the installed base and the severity of the threats. Apple’s decision to keep backporting fixes to iOS 16 sends a clear signal: these devices are still worth defending.

Who’s Still Running These Devices — and What They Should Do Right Now

The iPhone 8 launched in September 2017. The iPhone X, the same month. The iPad 5th generation hit shelves in March 2017. These aren’t ancient devices by consumer electronics standards — many are still perfectly functional for everyday tasks. But they represent a population of users who, for financial or practical reasons, haven’t upgraded to newer hardware. And they’re disproportionately vulnerable.

Research from analytics firms consistently shows that a significant portion of the global iPhone installed base runs models two or more generations behind the current release. In emerging markets, the share is even higher. These users often don’t follow security news. They may have automatic updates turned off, or they may dismiss update notifications without acting on them. So the gap between a patch being available and a patch being installed can stretch for weeks or months.

Here’s what to do if you’re affected. Open Settings, go to General, then Software Update. If you see iOS 16.7.13 or iPadOS 16.7.13 available, install it immediately. The update is small. It won’t take long. And it closes a hole that sophisticated attackers are already using in the wild.

If your device supports iOS 17 or iOS 18, you should be running the latest version of those operating systems instead. Apple patched the same underlying WebKit vulnerability in those branches earlier. Staying on iOS 16 when your hardware supports a newer OS means missing not just this patch but dozens of others.

For enterprise IT departments, this update demands attention. Organizations that maintain fleets of older iPads — common in retail, healthcare, and education — need to push this patch through their mobile device management systems now. A single unpatched device connected to a corporate network represents a potential entry point. And the attackers exploiting this vulnerability are, by Apple’s own description, sophisticated enough to be targeting specific individuals.

The broader question is how long Apple will continue supporting iOS 16 at all. The company hasn’t announced an end-of-life date for security updates to the platform, but each successive patch could be the last. Users relying on these older devices should plan accordingly. That doesn’t necessarily mean buying a new iPhone tomorrow. But it does mean understanding that the safety net gets thinner with every passing quarter.

Apple’s security model has always depended on tight integration between hardware and software. When devices age out of major OS support, that integration frays. Features like Lockdown Mode, Stolen Device Protection, and advanced Safari anti-tracking measures are unavailable on iOS 16. The security patches keep coming — for now. But they’re band-aids on devices that lack the full defensive architecture of Apple’s current platforms.

So update. Today. Not tomorrow, not this weekend. The exploit exists. The patch exists. The only variable is whether you install it before someone exploits the gap.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us