logo

Days After Google, Apple Reveals Exploited Zero-Day in Browser Engine

ID: bb3ff434-02dc-5d01-8d62-655fa4acb52e

STIX ID: report--bb3ff434-02dc-5d01-8d62-655fa4acb52e

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-23

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

Apple disclosed and patched an actively exploited WebKit zero-day (CVE-2024-23222) — a type confusion bug enabling arbitrary code execution — and acknowledged possible in-the-wild exploitation; the article links this to past abuses by commercial spyware vendors and notes concurrent browser-zero-day activity and a sharp increase in evasive, browser-based phishing attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.