Most Sophisticated iPhone Hack Ever Exploited Apple's Hidden Hardware Feature
ID: 9ef19d98-ca07-5c12-a847-b77171e4367f
STIX ID: report--9ef19d98-ca07-5c12-a847-b77171e4367f
Feed Name: The Hacker News
Operation Triangulation is a sophisticated zero-click iOS spyware campaign active since around 2019 and uncovered by Kaspersky; attackers used an iMessage PDF attachment to trigger a chain of four zero-day vulnerabilities that achieved arbitrary code execution and ultimately deployed spyware on devices up to iOS 16.2. The report highlights the CVEs involved (CVE-2023-41990, CVE-2023-32434, CVE-2023-32435, CVE-2023-38606), with CVE-2023-38606 enabling a novel hardware security bypass via undocumented MMIO registers on Apple A12–A16 SoCs, and places the operation in the broader context of state-linked surveillance and prior Pegasus-related campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
