Apple fixes iOS zero-day exploited by hackers

Apple fixes iOS zero-day exploited by hackers

Apple has released security updates for its iOS, iPadOS, macOS, and Safari products to address a zero-day vulnerability that has been actively exploited in hacker attacks.

Tracked as CVE-2023-23529, the bug is a type confusion issue in the Webkit browser engine that can be used by a remote attacker to achieve remote code execution by tricking a victim into visiting a specially crafted website. This type confusion issue was addressed with improved checks, the iPhone maker said.

The zero-day affects iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later, Macs running macOS Ventura.

Apple did not provide any details regarding attacks this flaw has been exploited in, only saying that “is aware of a report that this issue may have been actively exploited.”

Besides CVE-2023-23529, the tech giant patched a use-after-free issue (CVE-2023-23514) within OS kernel that could be abused by a local application to execute arbitrary code with kernel privileges.

Last month, Apple issued security updates for macOS, iOS, iPadOS, and WatchOS, to address a zero-day vulnerability in WebKit impacting older devices running iOS v12.

Tracked as CVE-2022-42856, the zero-day is type confusion issue that allows a remote attacker to achieve remote code execution by tricking the victim into visiting a malicious website.


Back to the list

Latest Posts

Cyber Security Week in Review: June 6, 2025

Cyber Security Week in Review: June 6, 2025

In brief: a critical vBulletin bug is being exploited in the wild, new destructive PathWiper malware targets Ukraine, and more.
6 June 2025
New PathWiper malware targets critical infrastructure in Ukraine

New PathWiper malware targets critical infrastructure in Ukraine

PathWiper shares several characteristics with Sandworm's HermeticWiper, which was used in attacks against Ukraine in 2022.
5 June 2025
US seizes 145 domains linked to BidenCash carding forum

US seizes 145 domains linked to BidenCash carding forum

It is estimated that the operation generated more than $17 million in revenue since launching in March 2022.
5 June 2025