ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1048
Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048)

CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent.

Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets.

7.81% KEV
  • Google Android (kernel)
mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown)
CVE-2021-37973
Use-After-Free Sandbox Escape in Google Chrome/Chromium Portals

CVE-2021-37973 is a use-after-free (CWE-416) in the Portals feature of Google Chrome prior to 94.0.4606.61. It is triggered via a crafted HTML page, and per the vendor description it allows a remote attacker who has already compromised the renderer process to potentially escape Chrome's sandbox; the CVSS vector confirms network reachability with required user interaction (UI:R). A successful exploit turns a renderer-level compromise into code execution outside the sandbox, with high impact to confidentiality, integrity, and availability (scope change, 9.6 critical). Anyone running Chrome or Chromium builds before 94.0.4606.61 is affected, including the chromium packages shipped by Fedora and Debian. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2021-11-03, Google patched it as one of two actively exploited Chrome zero-days (EPSS 11.6%, 96th percentile), no public PoC is known, and related reporting ties the era's actively exploited Chrome zero-days to mercenary spyware such as Intellexa/Cytrox's Predator.

Do: Upgrade Google Chrome to 94.0.4606.61 or later (confirm the running version at chrome://version) and update the chromium packages on Fedora and Debian to their patched builds. Because the flaw is on the CISA KEV list, applying vendor updates is required for federal and critical-infrastructure environments; enable automatic browser updates and prioritize patching where users browse untrusted web content, since exploitation is typically delivered via crafted pages in a chain.

9.612% KEV
  • google chrome prior to 94.0.4606.61
  • fedora (chromium browser package) chromium builds prior to the upstream 94.0.4606.61 fix (specific package versions not stated in source data)
  • debian linux (chromium package) chromium builds prior to the upstream 94.0.4606.61 fix (specific package versions not stated in source data)
mass≈3 billion Chrome users/installs (Chrome holds roughly 65% global browser share), plus Chromium users on Fedora and Debian
CVE-2021-37976
Information Disclosure in Google Chrome/Chromium Memory Implementation (CVE-2021-37976)

A memory implementation flaw (inappropriate implementation, tracked as CWE-862) in Google Chrome and Chromium prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from browser process memory. The flaw is reachable over the network with low complexity: an attacker needs no privileges but must convince a user (user interaction required) to load a crafted HTML page, e.g. by visiting an attacker-controlled website. A successful attacker gains read access to potentially sensitive data from the affected process's memory, with no direct impact on integrity or availability per the CVSS score. All Chrome/Chromium users running builds older than 94.0.4606.71 are affected, including Chromium as packaged and distributed by Fedora and Debian. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV on 2021-11-03 (ransomware use unknown), EPSS puts 30-day exploitation probability at 19.7% (97th percentile), and reporting around the Intellexa leaks ties the Chrome zero-day fixes of this period to Cytrox/Predator mercenary spyware operations.

Do: Upgrade Google Chrome/Chromium to 94.0.4606.71 or later immediately, per the CISA KEV required action; on Fedora and Debian, apply the distribution's Chromium security updates. Audit endpoints for browser versions below 94.0.4606.71 and prioritize internet-facing or high-value users given known in-the-wild exploitation and links to Predator spyware campaigns. No reliable mitigation short of updating exists; restricting browsing with unpatched builds reduces exposure.

6.520% KEV PoC
  • google chrome prior to 94.0.4606.71
  • google chromium prior to 94.0.4606.71 (CISA lists Google Chromium as affected)
  • fedoraproject fedora
  • +1 more
massbillions of users (Chrome is the dominant desktop browser at roughly 60-65% market share; the vulnerable population before the October 2021 fix was effectively…
CVE-2021-38000
Improper Input Validation in Google Chrome for Android Allows Forced URL Navigation

CVE-2021-38000 is an insufficient input validation flaw in the Intents component of Google Chrome on Android (CWE-20/CWE-601), allowing a remote attacker to make the browser navigate to an arbitrary, attacker-chosen URL by luring the user to a crafted HTML page. It is essentially a forced-navigation/open-redirect bug: the user must interact with the malicious page (user interaction required), and the attacker gains limited confidentiality and integrity impact by steering the browser to a malicious URL, which is typically chained with other flaws. The bug was fixed in Chrome 95.0.4638.69 for Android, and the flaw is also tracked against Chromium packages distributed in Fedora and Debian. It carries a CVSS 3.1 score of 6.1 (medium) and an EPSS of 4.7% (91st percentile). Exploitation is confirmed in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and contemporaneous headlines describe Google patching actively exploited Chrome zero-days, with press reports linking Chrome zero-day attacks on Android users to Predator spyware campaigns.

Do: Update Chrome on Android to version 95.0.4638.69 or later — since Chrome auto-updates, verify the installed version via Settings > About Chrome on managed and BYOD devices. Fedora and Debian users should install the current Chromium/Chrome security updates from their distribution. Inventory mobile fleets and internet-facing kiosk/device estates for Chrome builds below 95.0.4638.69 and treat user lures to crafted web pages as the primary delivery vector.

6.15% KEV PoC
  • Google Chrome (Android) All versions prior to 95.0.4638.69
  • Fedora Project Fedora Linux (Chromium/Chrome package) Distro-packaged builds prior to the upstream fix (95.0.4638.69); exact Fedora package versions not specified in source data
  • Debian Linux (Chromium/Chrome package) Distro-packaged builds prior to the upstream fix (95.0.4638.69); exact Debian package versions not specified in source data
mass≈1 billion+ Chrome for Android users (Chrome is the dominant browser on Android's multi-billion-device install base)
CVE-2021-38003
Memory Corruption in Chromium V8 JSON.stringify Affects Chrome, Edge, Opera

CVE-2021-38003 is a memory corruption flaw in the V8 JavaScript engine used by Chromium, in which the engine's internal 'TheHole' sentinel value can leak into script-visible data during JSON.stringify processing (a heap-corruption condition tracked as CWE-122 and CWE-755). It is triggered when crafted JavaScript causes JSON.stringify to expose this internal value to script code. An attacker who can induce a victim to load malicious web content can leverage the resulting corruption, typically chained with further techniques, to execute code within the browser renderer or crash it. All users of Chromium-based browsers — explicitly including Google Chrome, Microsoft Edge, and Opera, and by extension other Chromium derivatives — are affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03, carries a 38.6% EPSS probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Update all Chromium-based browsers (Chrome, Edge, Opera, and any Chromium-embedded or Electron-style applications in your estate) to the latest vendor-patched releases, per the CISA KEV required action to apply updates per vendor instructions. Verify remediated browser versions via enterprise update management and browser version reporting, prioritizing user workstations and externally reachable systems. Because exploitation is confirmed in the wild, treat unpatched Chromium browsers as an active exposure rather than a theoretical risk.

8.839% KEV PoC
  • Google Chromium V8 (JavaScript engine)
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
mass≈3 billion users (combined Chromium-based browser install base, Chrome alone accounting for the large majority)
CVE-2023-2033
Type Confusion in Google Chromium V8 Engine Exploited in the Wild

CVE-2023-2033 is a type confusion flaw (CWE-843) in Google's Chromium V8 JavaScript engine that a remote attacker can trigger by convincing a user to load a crafted HTML page. Successful exploitation could lead to heap corruption in the browser, potentially allowing the attacker to execute code in the context of the affected browser. Because V8 underpins the entire Chromium ecosystem, users of Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browser or application are potentially affected. The flaw is already being exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-17, and EPSS assigns a 40.8% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome and every other Chromium-based browser in use (Microsoft Edge, Opera, Brave, etc.) to the latest vendor-supplied stable release, per CISA's KEV required action to apply updates per vendor instructions. Verify installed browser versions across managed endpoints and treat unpatched Chromium builds as actively exploited given the KEV listing and high EPSS score.

8.841% KEV
  • Google Chromium V8 engine
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
massbillions of users (Chrome alone has roughly 3 billion users; Chromium also powers Edge, Opera, Brave and many embedded applications)
CVE-2023-2136
Skia Integer Overflow Sandbox Escape in Google Chrome

An integer overflow (CWE-190) in Skia, the 2D graphics library used by Chrome's renderer, can be triggered by a crafted HTML page whose content drives Skia processing past the limits of its integer math. A remote attacker who has already compromised the Chrome renderer process — for example through a separate renderer flaw or a malicious page — can leverage the overflow to escape Chrome's renderer sandbox and gain broader code execution on the host. All Google Chrome and Chromium users running versions prior to 112.0.5615.137 are affected, including Chromium packages shipped by Debian and Fedora. The flaw is rated Critical (CVSS 3.1: 9.6) and carries Chromium security severity High, with an EPSS probability of 5.7% (93rd percentile) of exploitation within 30 days. It was added to CISA's Known Exploited Vulnerability catalog on 2023-04-21, and news reports describe it as an actively exploited Chrome zero-day for which Google rushed out the 112.0.5615.137 patch.

Do: Update Google Chrome to 112.0.5615.137 or later on all platforms, and install the corresponding Chromium security updates on Debian and Fedora systems. Because exploitation requires user interaction with a crafted page plus a pre-existing renderer compromise, prompt patching is the primary mitigation; verify via CISA KEV required actions that all managed browsers are updated and confirm Chrome versions in endpoint inventory.

9.66% KEV
  • Google Chrome all versions prior to 112.0.5615.137
  • Google Chromium Chromium builds with Skia code prior to the fix delivered in 112.0.5615.137
  • Debian Linux (chromium package)
  • +1 more
masson the order of billions of Chrome/Chromium users worldwide (~3+ billion installations; ~65% browser market share)
CVE-2023-3079
Type Confusion in Google Chromium V8 Engine Exploited in the Wild

CVE-2023-3079 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine that powers Google Chromium, triggerable remotely when a user visits or is directed to a specially crafted HTML page. Successful exploitation causes heap corruption, which a remote attacker can leverage to execute code within the affected browser's renderer process. Every browser or application built on the Chromium engine is potentially affected, explicitly including Google Chrome, Microsoft Edge, and Opera. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-07 with a required action to apply vendor updates, and EPSS assigns a 32.1% probability of exploitation activity in the next 30 days (98th percentile). No public proof-of-concept code is known, but the KEV listing confirms real-world attacks, making rapid patching of all Chromium-based browsers a priority.

Do: Immediately update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers (including Chromium-embedded applications) to the latest vendor release, per the CISA KEV required action to apply updates per vendor instructions; confirm the update applied via the browser's About/Settings page. As a stopgap where patching is delayed, restrict browsing to trusted sites or disable JavaScript where feasible, since exploitation requires the renderer to process a crafted HTML page.

8.832% KEV PoC
  • Google Chromium V8 engine
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +1 more
mass3+ billion users (Chrome's global install base alone; Chromium-based Edge and Opera add hundreds of millions more)
CVE-2023-41993
+2 in the same advisory: …41992 …41991
WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari

Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known.

Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes.

8.8
group max
29% KEV
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • Apple macOS (WebKit)
  • +2 more
mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS)
CVE-2023-4762
Chromium V8 Type Confusion (CVE-2023-4762) Enables RCE via Crafted Web Pages

CVE-2023-4762 is a type confusion bug (CWE-843) in the V8 JavaScript engine used by Google Chromium, allowing a remote attacker to execute arbitrary code in the context of the browser when a user visits or is redirected to a crafted HTML page. Because V8 is shared across Chromium-based browsers, the flaw affects Google Chrome, Microsoft Edge, Opera, and other Chromium derivatives, not just Chrome itself. Successful exploitation gives an attacker code execution within the browser process on the victim's machine, a common foothold for delivering further malware. Google patched the bug in Chrome 116.0.5845.179/.180 (September 2023); any Chromium-based browser built on unpatched V8 remains vulnerable, and no public proof-of-concept is known. CISA added CVE-2023-4762 to the Known Exploited Vulnerabilities catalog on 2024-02-06, confirming exploitation in the wild (ransomware use unconfirmed), and EPSS assigns a ~41% probability of exploitation within 30 days (99th percentile).

Do: Patch all Chromium-based browsers fleet-wide to Chrome 116.0.5845.179/.180 or later and each vendor's equivalent (current Edge, Opera, Brave, etc.), consistent with the CISA KEV required action to apply vendor mitigations or discontinue use. Verify Chromium/V8 browser versions in your endpoint inventory before and after rollout; since exploitation is triggered by a crafted web page, interim mitigations include restricting unpatched machines' browsing and warning users about unsolicited links.

8.841% KEV
  • Google Chromium V8 Prior to the September 2023 fix (Chrome 116.0.5845.179/.180 per Google's stable channel advisory); source data does not specify an exact affected range
  • Google Chrome (ships affected V8) Chrome versions before 116.0.5845.179 (Windows/macOS) and 116.0.5845.180 (Linux), per Google's advisory
  • Microsoft Edge (Chromium-based, uses V8)
  • +1 more
massbillions of users (Chromium-based browsers dominate global usage; Chrome alone has ~3+ billion users)
CVE-2024-4610
Use-After-Free in Arm Mali Bifrost/Valhall GPU Kernel Drivers Exploited in the Wild

CVE-2024-4610 is a use-after-free (CWE-416) in Arm's Bifrost and Valhall Mali GPU kernel drivers, affecting driver builds from r34p0 through r40p0. A local, non-privileged user can trigger improper GPU memory processing operations that cause the driver to access already-freed memory. A successful exploit can yield high-impact outcomes — confidentiality, integrity and availability are all rated high, implying kernel-level information disclosure or code execution in the context of the GPU driver — and it could also be chained with other bugs in remote exploitation chains. Any device shipping a Mali Bifrost/Valhall driver in the affected range is exposed, including Android smartphones and other SoC-based products from vendors that integrate Mali GPUs. The flaw is being actively exploited in the wild: Arm warned of in-the-wild zero-day use, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-12, and related reporting ties it to spyware-grade exploitation (Intellexa/Predator and a Google warning about a Pixel firmware zero-day).

Do: Update to a fixed Arm Mali Bifrost/Valhall GPU kernel driver release newer than r40p0, which for most users means applying the latest Android/SoC/device vendor firmware updates (e.g., Google's updated Pixel firmware). Organizations managing fleets should inventory devices built on affected Mali driver versions (Pixel, MediaTek Dimensity, Exynos handsets; Rockchip/Amlogic boards) and prioritize them for patching given confirmed in-the-wild exploitation. Federal agencies must apply vendor mitigations per CISA KEV requirements within the mandated deadline, and defenders should treat local or chained remote exploitation paths as realistic, consistent with the spyware-usage reporting.

7.8<1% KEV
  • Arm Bifrost GPU Kernel Driver r34p0 through r40p0
  • Arm Valhall GPU Kernel Driver r34p0 through r40p0
mass≈hundreds of millions of Android devices and SoC-based systems with Mali Bifrost/Valhall GPUs in the affected driver range
CVE-2025-48543
Use-After-Free in Android Runtime Enables Sandbox Escape and Local Privilege Escalation

CVE-2025-48543 is a use-after-free (CWE-416) in the Android Runtime that exists in multiple code locations and allows an attacker who has already achieved code execution inside the Chrome sandbox to escape and attack the Android system_server process. The trigger requires only local access to the vulnerable component, with no additional execution privileges and no user interaction needed for exploitation. A successful attacker gains local escalation of privilege in the Android system server, making the bug especially useful as a privilege-escalation link in exploit chains against Android devices. Any Android device from Google's platform is in scope per CISA's listing (vendor: Google, product: Android, component: Android Runtime); specific affected version ranges are not enumerated in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-09-04 and Google's related headlines indicate it is being actively exploited in the wild; EPSS currently estimates only a 0.5% probability of exploitation in the next 30 days, and ransomware use is listed as unknown.

Do: Apply Google's Android security updates (September 2025 security bulletin patch level or later) as soon as they are available for your devices, since this flaw is listed in CISA's KEV and reported as exploited in the wild; per KEV required action, federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Use MDM/EDR tooling to verify device security patch levels, and note that because this is a sandbox-escape-to-system_server bug, it is most dangerous when chained with a browser/renderer exploit, so keeping Chrome/WebView current matters as well.

8.8<1% KEV
  • Google Android (Android Runtime component)
masson the order of billions of devices (Android runs on roughly 3 billion+ active devices worldwide, and the Android Runtime/system_server component is present on…
CVE-2025-6554
Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

8.113% KEV
  • Google Chrome all versions prior to 138.0.7204.96
  • Google Chromium V8 JavaScript engine V8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96
Full article1,370 words · extracted from thehackernews.com · click to collapse

A human rights lawyer from Pakistan's Balochistan province received a suspicious link on WhatsApp from an unknown number, marking the first time a civil society member in the country was targeted by Intellexa's Predator spyware, Amnesty International said in a report.

The link, the non-profit organization said, is a "Predator attack attempt based on the technical behaviour of the infection server, and on specific characteristics of the one-time infection link which were consistent with previously observed Predator 1-click links." Pakistan has dismissed the allegations, stating "there is not an iota of truth in it."

The findings come from a new joint investigation published in collaboration with Israeli newspaper Haaretz, Greek news site Inside Story, and Swiss tech site Inside IT. It's based on documents and other materials leaked from the company, including internal documents, sales and marketing material, and training videos.

Intellexa is the maker of a mercenary spyware tool called Predator that, similar to NSO Group's Pegasus, can covertly harvest sensitive data from targets' Android and iOS devices without their knowledge. The leaks show that Predator has also been marketed as Helios, Nova, Green Arrow, and Red Arrow.

Often, this involves using different initial access vectors like messaging platforms that weaponize previously undisclosed flaws to stealthily install the spyware either via a zero-click or 1-click approach. In the case of the latter, the attack requires a malicious link to be opened in the target's phone in order to trigger the infection.

Should the victim end up clicking the booby-trapped link, a browser exploit for Google Chrome (on Android) or Apple Safari (on iOS) is loaded to gain initial access to the device and download the main spyware payload. According to data from Google Threat Intelligence Group (GTIG), Intellexa has been linked to the exploitation of the following zero-days, either developed in-house or procured from external entities -

One such iOS zero-day exploit chain used against targets in Egypt in 2023 involved leveraging CVE-2023-41993 and a framework named JSKit to perform native code execution. GTIG said it observed the same exploit and framework used in a watering hole attack orchestrated by Russian government-backed hackers against Mongolian government websites, raising the possibility that the exploits are being sourced from a third-party.

Marketing brochure presenting the capabilities of Intellexa’s spyware product

"The JSKit framework is well maintained, supports a wide range of iOS versions, and is modular enough to support different Pointer Authentication Code (PAC) bypasses and code execution techniques," Google explained. "The framework can parse in-memory Mach-O binaries to resolve custom symbols and can ultimately manually map and execute Mach-O binaries directly from memory."

Screenshot of an example PDS (Predator Delivery Studio) dashboard interface used to manage targets and view collected surveillance data

Following the exploitation of CVE-2023-41993, the attack moved to the second stage to break out of the Safari sandbox and execute an untrusted third-stage payload dubbed PREYHUNTER by taking advantage of CVE-2023-41991 and CVE-2023-41992. PREYHUNTER consists of two modules -

  • Watcher, which monitors crashes, makes sure that the infected device does not exhibit any suspicious behavior, and proceeds to terminate the exploitation process if such patterns are detected
  • Helper, which communicates with the other parts of the exploit via a Unix socket and deploys hooks to record VoIP conversations, run a keylogger, and capture pictures from the camera

Intellexa is also said to be using a custom framework that facilitates the exploitation of various V8 flaws in Chrome – i.e., CVE-2021-38003, CVE-2023-2033, CVE-2023-3079, CVE-2023-4762, and CVE-2025-6554 – with the abuse of CVE-2025-6554 observed in June 2025 in Saudi Arabia.

Once the tool is installed, it collects data from messaging apps, calls, emails, device locations, screenshots, passwords, and other on-device information and exfiltrates them to an external server physically located in the customer's country. Predator also comes fitted with the ability to activate the device's microphone to silently capture ambient audio and leverage the camera to take photos.

The company, along with some key executives, was subjected to U.S. sanctions last year for developing and distributing the surveillance tool and undermining civil liberties. Despite continued public reporting, Recorded Future's Insikt Group disclosed in June 2025 that it detected Predator-related activity in over a dozen countries, primarily in Africa, suggesting "growing demand for spyware tools."

Perhaps the most significant revelation is that people working at Intellexa allegedly had the capability to remotely access the surveillance systems of at least some of its customers, including those located on the premises of its governmental customers, using TeamViewer.

"The fact that, at least in some cases, Intellexa appears to have retained the capability to remotely access Predator customer logs – allowing company staff to see details of surveillance operations and targeted individuals raises questions about its own human rights due diligence processes," Jurre van Bergen, technologist at Amnesty International Security Lab, said in a news release.

"If a mercenary spyware company is found to be directly involved in the operation of its product, then by human rights standards, it could potentially leave them open to claims of liability in cases of misuse and if any human rights abuses are caused by the use of spyware."

The report has also highlighted the different delivery vectors adopted by Intellexa to trigger the opening of the malicious link without the need for the target to manually click on it. This includes tactical vectors like Triton (disclosed in October 2023), Thor, and Oberon (both unknown at this stage), as well as strategic vectors that are delivered remotely via the internet or mobile network.

The three strategic vectors are listed below -

  • Mars and Jupiter, which are network injection systems that require cooperation between the Predator customer and the victim's mobile operator or internet service provider (ISP) to stage an adversary-in-the-middle (AitM) attack by waiting for the target to open an unencrypted HTTP website to activate the infection or when the target visits a domestic HTTPS website that's been already intercepted using valid TLS certificates.
  • Aladdin, which exploits the mobile advertising ecosystem to carry out a zero-click attack that's triggered simply upon viewing the specially-crafted ad. The system is believed to have been under development since at least 2022.

"The Aladdin system infects the target's phone by forcing a malicious advertisement created by the attacker to be shown on the target's phone," Amnesty said. "This malicious ad could be served on any website which displays ads."

Mapping of Intellexa's corporate web linked to Czech cluster

Google said the use of malicious ads on third-party platforms is an attempt to abuse the advertising ecosystem for fingerprinting users and redirecting targeted users to Intellexa's exploit delivery servers. It also said it worked with other partners to identify the companies Intellexa created to create the ads and shut those accounts.

In a separate report, Recorded Future said it discovered two companies called Pulse Advertise and MorningStar TEC that appear to be operating in the advertising sector and are likely tied to the Aladdin infection vector. Furthermore, there is evidence of Intellexa customers based in Saudi Arabia, Kazakhstan, Angola, and Mongolia still communicating with Predator's multi-tiered infrastructure.

"In contrast, customers in Botswana, Trinidad and Tobago, and Egypt ceased communication in June, May, and March 2025, respectively," it added. "This may indicate that these entities discontinued their use of Predator spyware around those times; however, it is also possible that they merely modified or migrated their infrastructure setups."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/12/intellexa-leaks-reveal-zero-days-and.html