Security News > 2020 > April > Apple Pushes Back Against Zero-Day Exploit Claims
![Apple Pushes Back Against Zero-Day Exploit Claims](/static/build/img/news/apple-pushes-back-against-zero-day-exploit-claims.jpg)
Apple has pushed back against claims that two zero-day bugs in its iPhone iOS have been exploited for years, saying it's found no evidence to support such activity.
Apple officials made the statement in response to a widely disseminated report published Wednesday by ZecOps, which claimed that two Apple iOS zero-day security vulnerabilities affecting its Mail app on iPhones and iPads already had been exploited in the wild since 2018 by an "Advanced threat operator."
Apple said in a statement to Bloomberg's Apple correspondent Mark Gurman that he posted on Twitter that this is just not true.
Over April 15 and 16, Apple began making a patch available to mitigate the security flaws in its publicly available beta software.
Apple did not address ZecOps claims that it worked with the company to identify the flaws, but did stress that it depends on its joint efforts with security researchers to identify flaws in its products to protect user security.
News URL
https://threatpost.com/apple-pushes-back-against-zero-day-exploit-claims/155108/
Related news
- New Mirai botnet targets industrial routers with zero-day exploits (source)
- Zero-day exploits plague Ivanti Connect Secure appliances for second year running (source)
- Nominet probes network intrusion linked to Ivanti zero-day exploit (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
- Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025 (source)
- Apple fixes this year’s first actively exploited zero-day bug (source)
- Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More (source)
- Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) (source)
- New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits (source)
- XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells (source)