* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, March 14, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Labrinth Calls Out the Entertainment Industry and ‘Euphoria’ in Mysterious Post

    The Try Guys Embark on an Unforgettable Journey Through the Soul of New Orleans: Jazz, Burlesque, Voodoo, and Beyond!

    Get Inspired This Weekend with Fresh Ideas for Going Green

    Seattle’s Wing Luke Museum Announces Exciting New Executive Director

    Golden Nugget Owner Eyes Major Acquisition of Caesars Entertainment

    Inspired Entertainment Unveils Exciting Q4 2025 Earnings Results

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    DexCom’s Next Chapter: Unlocking Exciting Growth in Glucose Monitoring Technology

    Is Keysight Technologies (KEYS) Powering the Future of the Technology Sector?

    Eight Midwestern Universities Unite to Launch Innovative Technology Hub in San Francisco

    Top Industry Experts Reveal Crucial Insights on Globant SA and Uber Technologies

    JIATF 401 Publishes Guide to Counter-Drone Technology and Privacy Protections – U.S. Department of War (.gov)

    Could This Technology Pose the Greatest Threat to American Democracy?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Labrinth Calls Out the Entertainment Industry and ‘Euphoria’ in Mysterious Post

    The Try Guys Embark on an Unforgettable Journey Through the Soul of New Orleans: Jazz, Burlesque, Voodoo, and Beyond!

    Get Inspired This Weekend with Fresh Ideas for Going Green

    Seattle’s Wing Luke Museum Announces Exciting New Executive Director

    Golden Nugget Owner Eyes Major Acquisition of Caesars Entertainment

    Inspired Entertainment Unveils Exciting Q4 2025 Earnings Results

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    DexCom’s Next Chapter: Unlocking Exciting Growth in Glucose Monitoring Technology

    Is Keysight Technologies (KEYS) Powering the Future of the Technology Sector?

    Eight Midwestern Universities Unite to Launch Innovative Technology Hub in San Francisco

    Top Industry Experts Reveal Crucial Insights on Globant SA and Uber Technologies

    JIATF 401 Publishes Guide to Counter-Drone Technology and Privacy Protections – U.S. Department of War (.gov)

    Could This Technology Pose the Greatest Threat to American Democracy?

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Apple fixes three vulnerabilities found by spyware researchers

September 25, 2023
in Technology
Apple fixes three vulnerabilities found by spyware researchers
Share on FacebookShare on Twitter

Apple has patched three more vulnerabilities uncovered by spyware and surveillance researchers at The Citizen Lab

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 25 Sep 2023 13:45

Apple has once again moved to lock down zero-day vulnerabilities uncovered by researchers specialising in commercial spyware and government surveillance, issuing a new patch for iPhone and Mac devices on Thursday 21 September.

The update covers CVE-2023-2023-41991, CVE-2023-41992 and CVE-2023-41993 in iOS, and CVE-2023-41991 and CVE-2023-41992 in macOS Ventura. Between them, these cover iPhone XS and later, iPad Pro 12.9 inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, iPad mini 5th generation and later.

The first vulnerability, CVE-2023-41991, is a certificate validation issue that grants a malicious app the ability to bypass signature validation. The second, CVE-2023-41992, is an elevation of privilege (EoP) vulnerability affecting the device kernel. The third, CVE-2023-41993, affects the WebKit browser engine and enables a threat actor to achieve arbitrary code execution if the user can be lured to a malicious website.

Apple gave little further detail on any of these issues beyond stating it was “aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7”.

All three vulnerabilities are credited to Maggie Stone of the Google Threat Analysis Group (TAG) and Bill Marczak of The Citizen Lab at the University of Toronto’s Munk School.

This is the latest in a string of vulnerabilities in Apple devices disclosed by The Citizen Lab, a specialist research unit probing commercial spyware and government surveillance.

The involvement of The Citizen Lab in general suggests that the issue in question has been exploited by clients of commercial (also often referred to as mercenary) spyware makers, which tend to be government agencies spying on persons of interest.

In this case, The Citizen Lab has alleged that the vulnerabilities have been chained by the developer of the Predator spyware, which is produced by Cytrox, a North Macedonia based-developer that has been sanctioned by the US government and banned from Meta’s platforms. Cytrox has been linked to people closely associated with the disgraced spyware developer NSO Group, and former Israeli intelligence operatives.

In new intelligence published in the wake of Apple’s disclosure, The Citizen Lab said it found the exploit chain had been used to target Egyptian politician Ahmed Eltantawy after he declared his intention to run for President in upcoming elections.

The researchers said that Eltantawy was first targeted with Cytrox via links sent on SMS and WhatsApp. Then, in August and September of 2023, his Vodafone Egypt mobile connection was targeted via network injection when Eltantawy was automatically redirected to a site not using HTTPS encryption, where the malicious payload infected his device.

Even reckoning without their abuse by the private spyware sector, Klaus Schenk, senior vice-president of security and threat research at Verimatrix, said the impact of the vulnerabilities should make them highly concerning to any user regardless of their likelihood of being targeted for snooping.

“Privilege escalation, arbitrary code execution, and especially remote exploitable arbitrary code execution rank among the most dangerous issues for any computing system,” said Schenk. “It’s reassuring that Apple has not yet disclosed technical details of the attack vectors. Keeping that information private significantly reduces the risk of widespread exploits, since threat actors have less information to engineer effective attacks.

“For remote code execution to occur, a user would need to visit a website specifically crafted to leverage these vulnerabilities and distribute malicious code. With details undisclosed, the number of sites currently capable of mounting such an attack is likely very low.

“That said, Apple customers should immediately install these emergency security updates to protect themselves against potential targeted attacks. Timely patching is critical, as threat actors will eventually reverse engineer the fixes to understand the underlying flaws. By updating promptly, users ensure their devices cannot be compromised by attacks exploiting these particular zero-day vulnerabilities,” he said.

Users concerned about their own susceptibility to commercial spyware may wish to consider enabling Apple’s on-board Lockdown Mode, which is known to block this infection chain and others identified by The Citizen Lab.

Read more on Hackers and cybercrime prevention


Apple issues emergency patches for 3 zero-day bugs

AlexanderCulafi

By: Alexander Culafi


Google, Microsoft and Mozilla push browser updates to foil zero-day

AlexScroxton

By: Alex Scroxton


Browser companies patch critical zero-day vulnerability

ArielleWaldman

By: Arielle Waldman


Apple patches Blastpass exploit abused by spyware makers

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366553194/Apple-fixes-three-vulnerabilities-found-by-spyware-researchers

Tags: Applefixestechnology
Previous Post

Insights from launching a developer-led bank

Next Post

San Sebastian: Culinary Zinema’s ‘Pachacútec, the Improbable School’ Unveils Trailer (EXCLUSIVE)

Unveiling the Diversity, Ecology, Cell Biology, and Evolution of Asgard Archaea

March 14, 2026

O-Zone: Evangel 79, Science and Arts 74 – KY3

March 14, 2026

How Course-Based Research Experiences Are Unlocking Exciting New Frontiers in Science

March 14, 2026

New Owner Cuts Majority of Staff at Three Salt Lake Magazines

March 14, 2026

Kiké Seizes the Moment to Shine for Puerto Rico on the World Stage

March 14, 2026

Iran Threatens to Cripple Global Economy as Trump Declares Regime’s Imminent Collapse

March 14, 2026

Labrinth Calls Out the Entertainment Industry and ‘Euphoria’ in Mysterious Post

March 14, 2026

Fourth Purdue AMR Conference Promotes Collaboration to Address Global Health Threat of Antimicrobial Resistance through PVM’s One Health Initiative. – Purdue University College of Veterinary Medicine

March 14, 2026

The Rundown | Last Week in Michigan Politics (3-13-26) – WZZM13.com

March 14, 2026

DexCom’s Next Chapter: Unlocking Exciting Growth in Glucose Monitoring Technology

March 14, 2026

Categories

Archives

March 2026
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
3031  
« Feb    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,117)
  • Economy (1,135)
  • Entertainment (22,012)
  • General (20,397)
  • Health (10,173)
  • Lifestyle (1,149)
  • News (22,149)
  • People (1,138)
  • Politics (1,153)
  • Science (16,351)
  • Sports (21,637)
  • Technology (16,118)
  • World (1,128)

Recent News

Unveiling the Diversity, Ecology, Cell Biology, and Evolution of Asgard Archaea

March 14, 2026

O-Zone: Evangel 79, Science and Arts 74 – KY3

March 14, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version