Security News > 2023 > June > Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!

Right at the start of June 2023, well-known Russian cybersecurity outfit Kaspersky reported on a previously unknown strain of iPhone malware.
Typically, iPhone malware that can compromise an entire device not only violates Apple's strictures about software downloads being restricted to the "Walled garden" of Apple's own App Store, but also bypasses Apple's much vaunted app separation, which is supposed to limit the reach of each app to a "Walled garden" of its own, containing only the data collected by that app itself.
That's because the kernel is responsible for all the "Walled gardening" protection applied to the device.
Therefore pwning the kernel generally means that attackers get to sidestep many or most of the security controls on the device altogether, resulting in the broadest and most dangerous sort of compromise.
Intriguingly, although Apple states no more than that the kernel zero-day "May have been exploited on iOS before version 15.7".
Every updated system, including watchOS and all three supported flavours of macOS, has been patched against this very kernel hole.
News URL
Related news
- Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks (source)
- CISA orders agencies to patch Linux kernel bug exploited in attacks (source)
- Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims (source)
- Apple fixes zero-day exploited in 'extremely sophisticated' attacks (source)
- Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200) (source)
- Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update (source)
- Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws (source)
- Patch Tuesday: Microsoft Patches Two Actively Exploited Zero-Day Flaws (source)
- We call this kernel saunters: How Apple rearranged its XNU core with exclaves (source)
- Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws (source)