ZeroHour
CyberScooppublished ()ingested @AJVicens

Apple issues emergency patch to address alleged spyware vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2023-32434CVE-2023-32435

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32435
+1 in the same advisory: …32434
Memory Corruption in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-32435 is an out-of-bounds write (CWE-787) memory corruption flaw in the WebKit engine shipped with Apple Safari, iOS, iPadOS, and macOS. It is triggered when WebKit processes maliciously crafted web content, such as a hostile webpage or embedded HTML, and successful exploitation leads to arbitrary code execution. Because WebKit is also used by non-Apple HTML parsers and applications, the impact extends beyond Safari and Apple's own browsers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-06-23, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. EPSS estimates a 22.8% probability of exploitation in the next 30 days (98th percentile), and a CVSS score is not yet published.

Do: Update Safari to 16.5 or later, iOS/iPadOS to 16.5 (or 15.7.6 on the legacy branch) or later, and macOS to the patched Ventura/Monterey/Big Sur releases (13.4 / 12.6.6 / 11.7.7) or later, then verify managed fleets are on fixed builds per the CISA KEV required action. Prioritize internet-exposed and high-risk users, since the flaw is confirmed exploited in the wild. If you ship or operate non-Apple products that embed WebKit, pull the fixed WebKit from the upstream project or your vendor.

8.8
group max
23% KEV
  • Apple Safari Versions prior to the WebKit fix shipped in Safari 16.5 (May 2023; see Apple advisory for exact ranges)
  • Apple iOS Versions prior to iOS 16.5 and the iOS 15.7.6 legacy-branch update
  • Apple iPadOS Versions prior to iPadOS 16.5 and the iPadOS 15.7.6 legacy-branch update
  • +2 more
mass>1,000,000,000 devices/users (WebKit is the system HTML engine on every iPhone and iPad and powers Safari on macOS)
Full article843 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The fix follows allegations from a Russian intelligence service that an intentional flaw in iPhones provided a gateway for American espionage.

(Justin Sullivan/Getty Images)

Apple issued a security update on Wednesday for all its operating systems to patch dangerous vulnerabilities that could allow attackers to take over someone’s entire device.

The vulnerabilities in question, first revealed on June 1, appeared to have led the main Russian intelligence agency to make unusually public claims that Apple intentionally left the flaws in its iOS so the National Security Agency and other U.S. entities could compromise “thousands” of iPhones in Russia. Apple has denied those claims.

The charges from the Federal Security Service, or FSB, came the same day that researchers with cybersecurity firm Kaspersky published a report detailing what they said was an “ongoing” zero-click iMessage exploit campaign dubbed “Operation Triangulation” targeting iOS that allowed attackers to run code on phones with root privileges, among other capabilities. Kaspersky published an additional analysis Wednesday, saying that after roughly six months of collecting and analyzing the data, “we have finished analyzing the spyware implant and are ready to share the details.”

Researchers with the cybersecurity firm that’s headquartered in Moscow said in the June 1 report they found the exploit “while monitoring the network traffic of our own corporate Wi-Fi network dedicated for mobile devices.”

Both Kaspersky analyses did not attribute the operators behind the campaign. A Kaspersky spokesperson told CyberScoop on Wednesday that the company had “nothing to provide” on attribution or in response to the FSB using Kaspersky’s work to backstop its claims of Apple collusion with the NSA and “American intelligence services.”

Kaspersky researchers “proactively collaborated with the Apple Security Research team by sharing information about the attack and reporting the exploits,” the spokesperson told CyberScoop in an email. “As of now, Apple has publicly confirmed them as zero-day vulnerabilities that received the designation of CVE-2023-32434 and CVE-2023-32435 respectively, and announced the patching of those as part of the Security Updates release on June 21, 2023. We would like to thank Apple for taking action promptly to address and resolve the identified issues to keep users safe.”

Apple said in its security update that the fixes would address an app that “may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.”

In response to the June 1 claims from the FSB, an Apple spokesperson told CyberScoop that “[we] have never worked with any government to insert a backdoor into any Apple product and never will.”

More Scoops

This aerial photograph shows demonstrators and students as they gather in front of Serbia’s Constitutional Court building during a protest to demand accountability for the Novi Sad railway station tragedy, in Belgrade, on January 12, 2025. Thousands of Serbians protested in the capital Belgrade on January 12, 2025, against corruption and demanding justice for those killed in a train station roof collapse. The demonstrations have been ongoing for two months since a roof in a train station in the northern city of Novi Sad, which had recently undergone restoration work, collapsed on November 1, 2024, and killed 15 people. (Photo by TADIJA ANASTASIJEVIC / AFP via Getty Images)

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…

Apple iOS update screen is seen displayed on a phone screen in this illustration photo taken in Krakow, Poland on Sept. 17, 2025. (Photo by Jakub Porzycki/NurPhoto)

DarkSword’s GitHub leak threatens to turn elite iPhone hacking into a tool for the masses

Darksword exploit kit
(Getty Images)

Second iOS exploit kit now in use by suspected Russian hackers

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-security-patch-kaspersky-russia-spyware/