Lucene search

K
hiveproHiveForce LabsHIVEPRO:E5A167A08A557B96664EB2560C4893F1
HistorySep 26, 2023 - 4:57 a.m.

Apple Addresses Zero-Day Flaws Exploited in the Wild

2023-09-2604:57:30
HiveForce Labs
www.hivepro.com
32
apple
zero-day
vulnerabilities
exploit
predator
spyware
iphone
cve-2023-41991
cve-2023-41992
cve-2023-41993
certificate validation
privilege escalation
remote code
web content
hiveforce labs

EPSS

0.014

Percentile

86.9%

Threat Level Vulnerability Report For a detailed threat advisory, download the pdf file here Summary Apple addressed three zero-day vulnerabilities used in an iPhone exploit chain to deliver the Predator spyware. The vulnerabilities involved were CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993. These vulnerabilities enabled attackers to bypass certificate validation, escalate privileges, and execute remote code on the targeted devices by using specially crafted web content. To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.