Apple
Curated coverage and analysis in this editorial area.

Apple Patches Zero-Day in dyld: A Flaw Hidden for Over a Decade
CVE-2026-20700 carries a CVSS 7.8 rating and is actively exploited against targeted individuals. Apple released patches on February 11…

DarkSword: JavaScript iOS Exploit Kit Strikes via Compromised Legitimate Sites
DarkSword chains six CVEs to compromise iPhones through compromised legitimate websites. The fileless, in-memory chain self-erases aft…

Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws
On June 29, 2026, Apple released iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2, addressing over 30 vulnerabilities.…

macOS: Standard Users Disable EDR/MDM Without Admin Rights
A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

ClickFix macOS: When Users Bypass Gatekeeper Themselves
Microsoft has documented the latest evolution of ClickFix campaigns on macOS: operators have ditched manual DMG installers for Termina…

Tata Electronics Breach: 200,000 Files Leaked, Apple and Tesla Secrets Appear on Dark Web
Tata Electronics confirmed a cybersecurity incident on June 22, 2026, stating it occurred "a few weeks ago" with no operational impact…

usbliter8: Unpatchable Exploit Hits Apple A12/A13 SecureROM
Paradigm Shift releases usbliter8, an unpatchable hardware exploit achieving arbitrary EL1 execution in Apple A12/A13 SecureROM via th…

Apple Beats: Bluetooth Flaw Turns Headphones Into Spy Microphones
Apple patched CVE-2025-20701 in Beats Studio Buds: attackers within Bluetooth range could eavesdrop on conversations by exploiting a f…

Apple macOS USD Library Flaw Enables Information Disclosure and Exploit Chaining
A vulnerability in the macOS Universal Scene Description (USD) library (ZDI-26-315) allows for out-of-bounds reads and potential code…

Apple Patches macOS RCE Vulnerability in USD Library (ZDI-26-314)
A critical out-of-bounds write in the macOS USD library could allow remote code execution through malicious 3D files. Apple released a…

macOS USD Library Bug ZDI-26-315 Exposes System Memory, Patch Issued May 12
Apple has addressed ZDI-26-315, an out-of-bounds read vulnerability in the macOS Universal Scene Description (USD) library. Rated CVSS…

Safari Regex Engine Vulnerability Allows Remote Code Execution via Duplicate Named Groups
Apple has patched a high-severity (CVSS 8.8) remote code execution vulnerability in Safari. The flaw involves a heap-based buffer over…