// 5 ZERO-DAY · 7 CVE · 4 EXPLOIT IN THE LAST 24H
Internal documents stolen from mercenary spyware vendor Intellexa reveal a systematic inventory of at least 14 zero-days for Android, iOS, Chrome, and Arm Mali GPUs, and document Predator's transformation into a SaaS model where the vendor directly operates surveillance on behalf of government clients via remote access.

Internal documents stolen from mercenary spyware vendor Intellexa have been analyzed by Amnesty International, Haaretz, and Inside Story, revealing a systematic inventory of at least 14 zero-days for Android, iOS, Chrome, and Arm Mali GPUs. The publication, dated August 11, 2026, documents for the first time Predator's transformation into a SaaS offering where the vendor not only sells the platform but directly operates government-client surveillance via remote access.

The technical dossier, corroborated by Google Threat Intelligence Group, exposes multi-stage exploit chains, new delivery vectors based on mobile programmatic advertising, and a structural violation of the separation between vendor and operator that exposes Intellexa to potential legal liability claims for human rights abuses.

Key Takeaways
  • Stolen documents confirm at least 14 zero-days for Android, iOS, Chrome, and Arm Mali GPUs, developed internally or sourced from external entities
  • Google TAG observed CVE-2025-6554 (V8 type confusion, CVSS 8.1) in in-the-wild activity in Saudi Arabia in June 2025
  • The Aladdin vector abuses the mobile advertising ecosystem for fingerprinting and silent redirect to exploit servers without user interaction
  • Intellexa staff have remote access to government clients' surveillance systems via TeamViewer, per a direct Amnesty International citation

The Zero-Day Catalog: From Chrome to Mali GPUs

Source 1 lists 14 specific CVEs associated with Intellexa operations, with convergence on technical details from primary vendor advisories. CVE-2025-6554, a type confusion in Chrome's V8 JavaScript engine with CVSS 8.1, was discovered by Clément Lecigne of Google Threat Intelligence Group and observed in-the-wild in Saudi Arabia in June 2025. CVE-2025-48543, a use-after-free in Android Runtime with CVSS 7.4, was confirmed by Google with active exploitation.

The documented iOS chain for 2023 combines three CVEs patched by Apple: CVE-2023-41993 (WebKit JIT RCE, CVSS 8.8), CVE-2023-41992 (kernel IPC use-after-free, CVSS 7.8), and CVE-2023-41991 (certificate validation bypass). This sequence, used against targets in Egypt, introduces the JSKit framework described by Google TAG as "well maintained, supports a wide range of iOS versions, and is modular enough to support different Pointer Authentication Code (PAC) bypasses and code execution techniques."

The framework operates in-memory with Mach-O execution, evading standard protections. Downstream, the PREYHUNTER payload articulates into Watcher modules, which monitor crashes and implement anti-analysis techniques, and Helper modules, which intercept VoIP calls and trigger camera capture. CVE-2024-4610, a use-after-free in Arm Mali Bifrost/Valhall GPUs, rounds out the picture with a hardware entry point rarely documented in mercenary spyware operations.

Aladdin and the Ad Arsenal: Zero-Click on the Programmatic Ecosystem

Among delivery vectors, the dossier distinguishes tactical and strategic. Triton, known since 2023, is joined by Thor and Oberon, whose operational details have not been disclosed. The strategic Mars/Jupiter vector implements Adversary-in-the-Middle (AitM) network injection with ISP or telco cooperation, a mode implying the potential unwitting complicity of legitimate communications infrastructure.

The most innovative element is Aladdin, in development since at least 2022. The system abuses the mobile programmatic advertising ecosystem for device fingerprinting and silent redirect to exploit servers, requiring no user interaction. Google collaborated on identifying and shutting down corporate accounts created by Intellexa to serve malicious ads. Recorded Future linked the operation to the companies Pulse Advertise and MorningStar TEC.

The brief does not specify whether Aladdin is currently operational in production or the exact nature of data exposed through the advertising vector.

The Surveillance Cloud: When the Vendor Becomes the Operator

The revelation that qualifies Intellexa's business model as a "surveillance cloud" is corporate staff's remote access to government client systems. The source directly quotes Jurre van Bergen, Amnesty International Security Lab: "The fact that, at least in some cases, Intellexa appears to have retained the capability to remotely access Predator customer logs – allowing company staff to see details of surveillance operations and targeted individuals raises questions about its own human rights due diligence processes."

The same source adds: "If a mercenary spyware company is found to be directly involved in the operation of its product, then by human rights standards, it could potentially leave them open to claims of liability in cases of misuse and if any human rights abuses are caused by the use of spyware." This configuration voids the theoretical separation between vendor and client that has historically shielded mercenary spyware companies from direct legal challenges.

The brief does not confirm whether TeamViewer access remains active or has been decommissioned, nor does it specify for which government clients it was implemented beyond the formulation "at least some of its customers."

Spyware Geography: Operations Despite Sanctions

Intellexa and its executives have been under U.S. sanctions since 2025 for exploit trafficking and threats to civil liberties. Despite this, Recorded Future detected Predator active in over a dozen countries, primarily in Africa, in June 2025. Source 1 lists active clients communicating with Predator infrastructure: Saudi Arabia, Kazakhstan, Angola, Mongolia; and former clients: Botswana, Trinidad and Tobago, Egypt.

Predator has also been marketed under the names Helios, Nova, Green Arrow, and Red Arrow, a rebranding strategy that complicates infrastructure tracking by defenders and regulators.

"The JSKit framework is well maintained, supports a wide range of iOS versions, and is modular enough to support different Pointer Authentication Code (PAC) bypasses and code execution techniques" — Google Threat Intelligence Group

Why It Matters

The brief does not document specific remedial measures or operational recommendations from the vendor. The source does not specify whether the 14 CVEs represent an exhaustive or partial inventory of Intellexa's zero-day arsenal, nor does it identify the exact origin of the stolen documents (whistleblower, breach, or former employee). The external entity from which Intellexa sourced some exploits is not named, and the operational role of Thor and Oberon remains undisclosed.

The source also does not clarify whether remote access via TeamViewer has been decommissioned or remains active. The publication date of Source 1 (2026-08-11) appears anomalous relative to content citing 2025 events; it may require verification.

For tech companies, the revelation imposes a new spyware risk calculus: zero-click advertising vectors expand the attack surface beyond traditional messaging platforms, implicating the entire mobile programmatic ecosystem. For telco operators and ISPs, AitM network injection raises compliance and legal liability questions. For governments and NGOs, the documentation of vendor access constitutes a precedent for the legal accountability of mercenary spyware providers.

The 2026 Question: Who Watches the Watcher?

The Intellexa dossier inverts the consolidated narrative of mercenary spyware as an autopilot product in government clients' hands. The documentation of remote access, active exploit framework maintenance, and the ability to view surveillance operation logs transforms the vendor from supplier to co-operator. This role redefinition, if confirmed in legal contexts, could erode the legal shelter that has allowed the sector to proliferate.

The persistence of operations despite U.S. sanctions, the diversification of vectors into programmatic advertising, and the modularity of iOS frameworks like JSKit suggest the mercenary spyware business model is evolving toward a more resilient, more diffuse, and harder-to-attribute structure. 2026 opens with proof that the vendor-client separation was, in at least one case, a convenient fiction.

Frequently Asked Questions

What specifically is the JSKit framework?

According to the direct Google Threat Intelligence Group citation in Source 1, it is a modular iOS framework that supports a wide range of OS versions, implements diverse Pointer Authentication Code bypasses, and executes Mach-O code directly from memory.

Why is TeamViewer access relevant beyond the single case?

Source 1 cites Amnesty International to argue that this practice, if documented as direct vendor involvement in operations, exposes Intellexa to legal liability claims for human rights abuses under international standards, breaking the conventional protection of mere technology provision.

What is the difference between tactical and strategic vectors in the dossier?

Source 1 classifies Triton, Thor, and Oberon as tactical vectors (direct payload delivery modes), while Mars/Jupiter and Aladdin are strategic vectors that leverage network infrastructure (AitM with ISPs) and the programmatic advertising ecosystem respectively to reach targets at scale.

Sources

Information is based on cited sources and current as of publication.

Sources


Sources and references
  1. thehackernews.com