iOS Zero-Day Exploit Chain Leveraged by Mercenary Spyware for Device Surveillance
ID: e7d33240-00e8-55e8-9cd2-8ccd727bd666
STIX ID: report--e7d33240-00e8-55e8-9cd2-8ccd727bd666
Feed Name: cybersecurityNews.com
A Google Cloud analysis links an active iOS zero-day exploit chain—attributed to the commercial surveillance vendor Intellexa and internally codenamed “smack”—to deployment of the Predator spyware family against civil society and political targets; the attack uses a one-time Safari link exploiting JSKit (CVE-2023-41993) to gain renderer code execution, then pivots via kernel vulnerabilities (CVE-2023-41992, CVE-2023-41991) to achieve system-level control and load PREYHUNTER modules that perform audio capture, keylogging, camera activation, sandbox escape, anti-analysis checks, and persistent covert surveillance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
