Cyber Security News

Apple Urgently Patches Zero-day Flaw Exploited in the Wild

Apple has released an emergency security update for patching two actively exploited zero-day vulnerabilities on iOS. The vulnerabilities were discovered earlier this month and are tracked as CVE-2023-42916, and CVE-2023-42917 affected many Apple products.

The security advisory from Apple has patched several vulnerabilities. Two of the most common vulnerabilities patched on this emergency update were CVE-2023-42890 and CVE-2023-42883.

All of these vulnerabilities existed in the WebKit browser engine of several Apple products such as macOS, iOS, and iPadOS.

CVE-2023-42916: Out of Bounds Read Vulnerability

This vulnerability exists in WebKit of iOS, iPadOS, macOS, and Safari, allowing a threat actor to perform an out-of-bounds read that could disclose sensitive information when processing web content. This vulnerability has been given a severity of 6.5 (Medium).

Apple has patched this vulnerability and implemented a proper input validation to prevent it.

Products affected by this vulnerability include iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

CVE-2023-42917: Memory Corruption Vulnerability

This vulnerability exists in the WebKit of iOS, iPadOS, macOS, and Safari, allowing an attacker to execute arbitrary code when processing web content.

The severity for this vulnerability has been given as 8.8 (High). Apple stated that they have patched this vulnerability by improving the locking. 

Products affected by this vulnerability include iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

Both of these vulnerabilities have been added to the CISA’s Known Exploited Vulnerability catalog to provide awareness to all the users of these products.

Apple urges its users to update their Apple products to the latest version to patch these vulnerabilities and prevent them from becoming victims of cybercriminals.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

New Kali Tool llm-tools-nmap Uses Nmap For Network Scanning Capabilities

Along with the release of Kali Linux 2025.3, a major update introduces an innovative tool that…

2 hours ago

New Chaosbot Leveraging CiscoVPN and Active Directory Passwords to Execute Network Commands

ChaosBot surfaced in late September 2025 as a sophisticated Rust-based backdoor targeting enterprise networks. Initial…

17 hours ago

Threat Actors Exploiting SonicWall SSL VPN Devices in Wild to Deploy Akira Ransomware

Threat actors have reemerged in mid-2025 leveraging previously disclosed vulnerabilities in SonicWall SSL VPN appliances…

17 hours ago

Nanoprecise partners with AccuKnox to strengthen its Zero Trust Cloud Security and Compliance Posture

Menlo Park, USA, October 10th, 2025, CyberNewsWire AccuKnox, a leader in Zero Trust Cloud Native…

18 hours ago

175 Malicious npm Packages With 26,000 Downloads Attacking Technology, and Energy Companies Worldwide

Socket's Threat Research Team has uncovered a sophisticated phishing campaign involving 175 malicious npm packages…

18 hours ago

RondoDox Botnet Exploits 50+ Vulnerabilities to Attack Routers, CCTV Systems and Web Servers

Since its emergence in early 2025, RondoDox has rapidly become one of the most pervasive…

19 hours ago