Apple
Curated coverage and analysis in this editorial area.

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time
Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

Apple Patches Decade-Old Zero-Day in iOS Core: dyld Exposed for 10+ Years
CVE-2026-20700 affects the dyld dynamic linker, a fundamental component present for over a decade. Apple confirms targeted exploitatio…

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS
Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild
DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

Apple Releases iOS 18.6.2: Zero-Click Spyware Patch for Active ImageIO Exploit
On August 20, 2025, Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework exploited in spyware attacks against…

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6
CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

Apple Patches ImageIO: Parsing Bug Opens Door to RCE Across Eight Operating Systems
A flaw in Apple's ImageIO framework allows remote code execution via malformed image files. Patches are available for eight operating…

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files
CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

Apple Patches iOS 26 dyld Zero-Day: Targeted Attacks Already Underway
Apple has released iOS 26.3 to address CVE-2026-20700, a zero-day vulnerability in the dyld component exploited in sophisticated attac…

DarkSword: The iOS Kit That Armed Three Spy Groups With Six Flaws
Google Threat Intelligence Group uncovered DarkSword, a full-chain iOS exploit kit written in JavaScript that has been active since No…

DarkSword and Coruna: Government-Grade Spyware Turns Mass Crime on iOS
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click…