Days After Google, Apple Reveals Exploited Zero-Day in Browser Engine
ID: bb3ff434-02dc-5d01-8d62-655fa4acb52e
STIX ID: report--bb3ff434-02dc-5d01-8d62-655fa4acb52e
Feed Name: Dark Reading
Threat Score
Apple disclosed and patched an actively exploited WebKit zero-day (CVE-2024-23222) — a type confusion bug enabling arbitrary code execution — and acknowledged possible in-the-wild exploitation; the article links this to past abuses by commercial spyware vendors and notes concurrent browser-zero-day activity and a sharp increase in evasive, browser-based phishing attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
