ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Mobile Security

New iOS and iPadOS update pushed to fix zero-day bugs

The zero-day bug has been patched after being seen used in the wild by cybercrime groups

Kyle by Kyle
February 17, 2023 - Updated on February 19, 2023
in Mobile Security
Reading Time: 3 mins read
apple ios ipados zero day update
Share on FacebookShare on Twitter

Cybercriminals and “commercial” spyware developers frequently target iOS devices to carry out surveillance operations, data theft, and other nefarious actions. By identifying a weakness in Apple’s iOS WebKit, hackers can take advantage of security flaws like the one that Apple has fixed in their most recent version of the iPhone and iPad operating systems.

Apple has released a patched version of iOS and iPadOS that addresses a couple of severe security flaws. One of the vulnerabilities is already being exploited by unknown cybercriminals in the wild. The flaw may be part of well-known cybercrime services sold to some of the world’s most dangerous organizations and foreign states, based on the individuals Apple has thanked for the release of these zero-days.

Information about the two fixed bugs is included in the release notes of both iOS 16.3.1 and iPadOS 16.3.1. The first vulnerability, CVE-2023-23514, is described as a “use after free issue” addressed with improved memory management. A malicious app designed to exploit the bug could execute arbitrary code with kernel-level privileges.

The second vulnerability, known as CVE-2023-23529, is the most dangerous one. It is described as a “type confusion issue” in the WebKit browser engine that could be used to create a malicious web page for executing arbitrary code. Apple said it is aware that the issue may have already been actively exploited, which suggests that security researchers informed the company that the zero-day vulnerability is already being used in a malicious campaigns targeting iPhone and iPad users.

Apple thanked Xinru Chi of Pangu Lab, Ned Williamson of Google Project Zero, and an anonymous researcher for discovering the two vulnerabilities. Apple also acknowledged the help they received from The Citizen Lab at The University of Toronto’s Munk School in addressing the flaws.

ios 16 security zero day patched

You might also like

How Hackers Still Manage to Compromise MFA

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

The Citizen Lab group is well known for its research work on dangerous hacking tools created by the NSO Group and sold to government agencies and police forces worldwide. The Israeli company is infamous for creating Pegasus, multi-platform spyware software designed to exploit zero-day flaws such as CVE-2023-23529 for smartphone-based surveillance operations.

According to several reports, Pegasus has been used to target human rights activists and journalists, carry out state espionage in Pakistan, and conduct domestic surveillance against Israeli citizens. It also played a role in the murder of Jamal Khashoggi by agents of the Saudi government.

Given the involvement of Pegasus hunters at Citizen Lab and Apple’s current silence on the issue, CVE-2023-23529 could be yet another weapon discovered in the powerful arsenal of commercial spyware and surveillance tools routinely used to target dissidents around the world.

Tags: IOSiPadOSzero day
Previous Post

BlueSky Ransomware Infects KMSAuto Activator users

Next Post

Android is getting firmware level security improvements

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026
Discover how the BadBox botnet infects 190,000+ Android devices, compromising smart TVs and smartphones across multiple countries with dangerous malware.

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

Massive Backdoor Infection Hits 1.3 Million Android-Based Streaming Devices

September 16, 2024

Cybercriminals Target Mobile Users in the Czech Republic with Phishing Campaigns Leveraging Progressive Web Applications

August 20, 2024

LianSpy: New Android Spyware Targeting Russian Users

August 7, 2024

New Mandrake Android Malware Variant Evades Detection on Google Play

July 29, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.