Security News > 2023 > September > Recently patched Apple, Chrome zero-days exploited in spyware attacks

Security researchers with The Citizen Lab and Google's Threat Analysis Group revealed today that three zero-days patched by Apple on Thursday were abused as part of an exploit chain to install Cytrox's Predator spyware.
Google TAG also observed the attackers using a separate exploit chain to drop Predator spyware on Android devices in Egypt, exploiting CVE-2023-4762-a Chrome bug patched on September 5th-as a zero-day to gain remote code execution.
Citizen Lab urged all Apple users at risk to install Apple's emergency security updates and enable Lockdown Mode to thwart potential attacks exploiting this exploit chain.
Citizen Lab security researchers disclosed two other zero-days-fixed by Apple in emergency security updates earlier this month-abused as part of another zero-click exploit chain to infect fully patched iPhones with NSO Group's Pegasus spyware.
Apple emergency updates fix 3 new zero-days exploited in attacks.
Google fixes another Chrome zero-day bug exploited in attacks.
News URL
Related news
- Apple fixes zero-day exploited in 'extremely sophisticated' attacks (source)
- Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200) (source)
- Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks (source)
- Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks (source)
- SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon (source)
- New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits (source)
- New Syncjacking attack hijacks devices using Chrome extensions (source)
- Meta Confirms Zero-Click WhatsApp Spyware Attack Targeting 90 Journalists, Activists (source)
- Google fixes Android kernel zero-day exploited in attacks (source)
- 7-Zip MotW bypass exploited in zero-day attacks against Ukraine (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-05 | CVE-2023-4762 | Type Confusion vulnerability in multiple products Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | 8.8 |