logo

Apple patches decade-old iOS zero-day, possibly exploited by commercial spyware

ID: 48586341-27ee-5873-93c3-06e13ed0d7ec

STIX ID: report--48586341-27ee-5873-93c3-06e13ed0d7ec

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-02-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Apple released iOS/iPadOS 26.3 to patch a critical zero-day (CVE-2026-20700) in the dyld dynamic linker—present since iOS 1.0—that Google TAG says was exploited in an "extremely sophisticated" attack against targeted individuals; when chained with WebKit flaws this provided a zero-click/one-click path to full device takeover. The report also notes two high-scoring Chrome vulnerabilities and likens the sophistication to exploits sold by commercial surveillance vendors such as Pegasus and Predator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.