logo

iOS Zero-Day Exploit Chain Leveraged by Mercenary Spyware for Device Surveillance

ID: e7d33240-00e8-55e8-9cd2-8ccd727bd666

STIX ID: report--e7d33240-00e8-55e8-9cd2-8ccd727bd666

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Google Cloud analysis links an active iOS zero-day exploit chain—attributed to the commercial surveillance vendor Intellexa and internally codenamed “smack”—to deployment of the Predator spyware family against civil society and political targets; the attack uses a one-time Safari link exploiting JSKit (CVE-2023-41993) to gain renderer code execution, then pivots via kernel vulnerabilities (CVE-2023-41992, CVE-2023-41991) to achieve system-level control and load PREYHUNTER modules that perform audio capture, keylogging, camera activation, sandbox escape, anti-analysis checks, and persistent covert surveillance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.