Apple launches an emergency update for this year’s tenth zero-day
Apple is launching a new set of Rapid Security Response (RSR) updates to address its tenth zero-day vulnerability in 2023. Reports say that the new zero-day has been exploited in attacks and impacted entirely up-to-date iPhones, Macs, and iPads. Found by Apple’s WebKit browser engine, the exploitation allowed attackers to gain arbitrary code execution on

Apple-launches-an-emergency-update-for-this-years-tenth-zero-day

Apple is launching a new set of Rapid Security Response (RSR) updates to address its tenth zero-day vulnerability in 2023.
Reports say that the new zero-day has been exploited in attacks and impacted entirely up-to-date iPhones, Macs, and iPads.
Found by Apple’s WebKit browser engine, the exploitation allowed attackers to gain arbitrary code execution on target devices by tricking users into opening malicious web pages. Apple revealed in its iOS and MacOS notices regarding the vulnerability that it is aware of a report that this issue may have been actively exploited.
“This Rapid Security Response provides important security fixes and is recommended for all users.” – the company added.
How Apple went about tackling the vulnerability was that it implemented improved checks to dampen exploitation attempts. This is the tenth zero-day impacting iPhones, Macs, and iPads that Apple has had to patch in 2023.
A similar incident that took place previously saw Apple address three vulnerabilities exploited to deploy triangulation spyware on iPhones. Kaspersky dubbed the iOS spyware campaign “Operation Triangulation”, and attackers could deploy the implant — TriangleDB — once they obtained root privileges on a target device by exploiting the kernel vulnerability.
Kaspersky said at the time that the spyware was deployed in memory, which meant that all traces of the implant were lost when the device gets rebooted. “Therefore, if the victim reboots their device, the attackers have to reinfect it by sending an iMessage with a malicious attachment, thus launching the whole exploitation chain again.” – Kaspersky added.
It also added that case no reboot occurs, the implant uninstalls itself after 30 days unless this period is extended by the attackers.
Before all of this took place, Apple addressed three zero-days in May, two in April, and another in February 2023.



