Security News > 2021 > March > Hacking group used 11 zero-days to attack Windows, iOS, Android users

Hacking group used 11 zero-days to attack Windows, iOS, Android users
2021-03-20 14:41

Project Zero, Google's zero-day bug-hunting team, discovered a group of hackers that used 11 zero-days in attacks targeting Windows, iOS, and Android users within a single year.

The Project Zero team revealed that the hacking group behind these attacks ran two separate campaigns, in February and October 2020.

The attackers used a couple of dozen websites hosting two exploit servers, each of them targeting iOS and Windows or Android users.

One full exploit chain targeting fully patched Windows 10 using Google Chrome.

Several RCE exploits for iOS 11-13 and a privilege escalation exploit for iOS 13.

In the case of the Chrome Freetype zero-day, the exploitation method used by this hacking group was new to Project Zero.


News URL

https://www.bleepingcomputer.com/news/security/hacking-group-used-11-zero-days-to-attack-windows-ios-android-users/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19