Security News > 2023 > June > Apple patch fixes zero-day kernel hole reported by Kaspersky – update now!

Right at the start of June 2023, well-known Russian cybersecurity outfit Kaspersky reported on a previously unknown strain of iPhone malware.
Typically, iPhone malware that can compromise an entire device not only violates Apple's strictures about software downloads being restricted to the "Walled garden" of Apple's own App Store, but also bypasses Apple's much vaunted app separation, which is supposed to limit the reach of each app to a "Walled garden" of its own, containing only the data collected by that app itself.
That's because the kernel is responsible for all the "Walled gardening" protection applied to the device.
Therefore pwning the kernel generally means that attackers get to sidestep many or most of the security controls on the device altogether, resulting in the broadest and most dangerous sort of compromise.
Intriguingly, although Apple states no more than that the kernel zero-day "May have been exploited on iOS before version 15.7".
Every updated system, including watchOS and all three supported flavours of macOS, has been patched against this very kernel hole.
News URL
Related news
- Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast (source)
- Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws (source)
- Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day (source)
- Apple fixes this year’s first actively exploited zero-day bug (source)
- Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More (source)
- Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) (source)
- Google fixes Android kernel zero-day exploited in attacks (source)
- CISA orders agencies to patch Linux kernel bug exploited in attacks (source)
- Apple missed screenshot-snooping malware in code that made it into the App Store, Kaspersky claims (source)
- Apple fixes zero-day exploited in 'extremely sophisticated' attacks (source)