Visualização normal

Antes de ontemSecurity Affairs
  • ✇Security Affairs
  • Apple warned hundreds of users of mercenary spyware attacks Pierluigi Paganini
    Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021. “Apple threat notifications are designed to inform and assi
     

Apple warned hundreds of users of mercenary spyware attacks

14 de Agosto de 2026, 14:09

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance.

Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021.

“Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices.” reads the alert. “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”

That alone should reset the usual mental model. This isn’t about a suspicious app, a recycled phishing email, or the kind of opportunistic malware that lands wherever it can. Apple’s alerts concern highly targeted attacks against particular people, often because of their role, their work, or the people they know.

The people most likely to receive these notifications include journalists, activists, politicians, diplomats, lawyers, and others whose devices may hold valuable conversations, contacts, documents, or location data. That does not mean every recipient has been fully compromised, but it does mean Apple has observed enough to treat the risk as credible.

Apple has also changed how it delivers those alerts. A recipient may see a push notification directly on the iPhone lock screen and in Settings, receive an email from threat-notifications@email.apple.com, and find a warning banner after signing in to their Apple Account. The company says genuine notices will never ask users to click a link, open a file, install a profile, or provide a password or verification code by email or phone.

“Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” continues the report. “We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”

That lack of detail can frustrate recipients. They want to know who targeted them, how the device was approached, and whether the attacker got in. Apple can’t safely answer most of those questions in public, because publishing the detection logic would give spyware vendors a free quality-assurance report. Nobody needs to make Pegasus-style operators more efficient.

If you receive the warning, don’t panic and don’t start improvising. First, verify it by signing in directly at account.apple.com: a genuine Apple threat notification appears at the top of the page. Then preserve the device, avoid unnecessary resets or changes until you have spoken to someone qualified, and seek expert help, such as the Digital Security Helpline run by Access Now.

Apple recommends enabling Lockdown Mode, its high-security setting designed to reduce the attack surface available to sophisticated spyware. It also advises keeping devices updated, using a strong passcode with Touch ID or Face ID, turning on two-factor authentication, enabling Stolen Device Protection, using strong and unique passwords or passkeys, installing apps only through the App Store, and treating unexpected links or attachments as hostile until proven otherwise.

“Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.” states the alert. “As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”

The wider value of these alerts goes beyond the device in front of the recipient. Citizen Lab researcher John Scott-Railton told TechCrunch that notifications can reveal that an entire community is being targeted, because people who receive them often seek help and their cases lead investigators to others.

Most people will never receive one of these warnings. Apple says that plainly, and it is worth repeating because not every cybersecurity story needs to become a universal panic. But if your phone shows an Apple notice saying it detected a targeted mercenary spyware attack, assume it matters until an expert tells you otherwise.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

  • ✇Security Affairs
  • Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools Pierluigi Paganini
    Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using AI tools, including Anthropic’s Claude and OpenAI’s Codex Security. That’s not a small detail. It changes who’s doing the hunting on the defensive side. The comp
     

Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools

30 de Junho de 2026, 08:32

Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex

Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using AI tools, including Anthropic’s Claude and OpenAI’s Codex Security. That’s not a small detail. It changes who’s doing the hunting on the defensive side.

The company addressed four bugs in WebKit, the engine that powers Safari and anything else on Apple devices that renders web content.

Below are the descriptions of the vulnerabilities:

  • CVE-2026-43707 – A memory corruption vulnerability in WebKit that can cause an unexpected process crash when handling specially crafted web content.
  • CVE-2026-43716 – A WebKit vulnerability that can trigger an unexpected Safari crash when processing maliciously crafted web content.
  • CVE-2026-43745 – An out-of-bounds write flaw in WebKit that can cause Safari to crash when a user visits specially crafted web content.
  • CVE-2026-43715 – A use-after-free vulnerability in WebKit that can lead to memory corruption when processing maliciously crafted web content.

They’re part of a much bigger patch load. Apple’s advisory lists close to 30 fixes across WebKit alone, including a use-after-free in WebKit Canvas and a flaw that let a malicious website pull restricted content out of the browser sandbox. On the kernel side, three separate bugs could have let a malicious app leak kernel state, crash the system outright, or corrupt kernel memory. Security researcher Hyunwoo Kim, known for finding the Dirty Frag exploit, gets credit for two of those kernel issues.

The updates are live now: iOS 26.5.2, iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2. Apple says none of the patched vulnerabilities show signs of having been exploited before the fix shipped. Update anyway, obviously, that’s not really optional advice anymore.

Why the timing matters more than usual? Here’s the part that’s actually new. Apple told Reuters it’s pushing these fixes out ahead of schedule, separate from the next full iOS release, because of how fast AI can now turn a known flaw into a working exploit. As one wire report put it,

“Unless security experts discover ​a hacking campaign targeting a previously unknown software flaw, Apple usually releases security ‌updates ⁠as part of a move from one version of iOS to the next, for example from the currently available version – 26.5 – to the next planned update, 26.6. In the interim, developers and ​other testers trial ​the next ⁠update to iron out any kinks.” states Reuters. “The company said that, instead, the latest round of security updates ​were being made available to everyone ahead of ​the ⁠wider release of 26.6. It said that while there was no evidence that any of the newly patched vulnerabilities had been taken ⁠advantage of, ​the time between the point when ​security fixes were first announced and when they were deployed to customers’ phones ​needed to be compressed.”

That’s a real departure from how Apple normally operates. The company typically bundles security fixes into the next big iOS version bump rather than shipping standalone patches. Reuters described this as “a notable change in Apple’s longstanding practice of packaging security fixes with broader software releases”, which tells you Apple sees the AI-acceleration problem as structural, not a one-off.

The Hacker News confirms that the patches address “flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools.” Same tools that can find these bugs for defenders can, in different hands, help find them for attackers. The race just got faster on both sides.

The irony is hard to miss. AI helped researchers find these flaws, but it’s also making it easier for attackers to discover and exploit bugs more quickly. That’s why Apple is moving faster to release security updates and reduce the time attackers have to take advantage of them.

If you’ve been delaying your updates, now is a good time to install them. While most of these flaws mainly cause crashes, attackers can often combine them with other vulnerabilities to carry out more serious attacks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

  • ✇Security Affairs
  • usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices Pierluigi Paganini
    usbliter8 is an unpatchable BootROM exploit affecting A12/A13 devices, enabling code execution and extending checkm8-like risks to newer iPhones. Security researchers at Paradigm Shift published a working exploit on June 18, 2026, called usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. SecureROM is the first code that runs when an Apple device boots. It’s burned into the silicon at manufacture and cannot be modified or patched after the fac
     

usbliter8 Brings Unpatchable BootROM Exploit to Apple A12 and A13 Devices

22 de Junho de 2026, 04:12

usbliter8 is an unpatchable BootROM exploit affecting A12/A13 devices, enabling code execution and extending checkm8-like risks to newer iPhones.

Security researchers at Paradigm Shift published a working exploit on June 18, 2026, called usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple’s A12 and A13 chips. SecureROM is the first code that runs when an Apple device boots. It’s burned into the silicon at manufacture and cannot be modified or patched after the fact. Every device carrying these chips will carry this vulnerability for its entire operational life.

“The usbliter8 exploit demonstrates that even on more recent SecureROM generations, including those protected by Pointer Authentication, subtle hardware bugs can still be leveraged to achieve full code execution and break the chain of trust.” reads the report published by Paradigm Shift.

The attack is not remote. The experts pointed out that it requires physical access to the device, DFU mode, a USB connection, and a dedicated RP2350-based microcontroller board.

The researchers published a working proof of concept on June 18, following coordinated disclosure with Apple Product Security. No CVE and no Apple security advisory had been issued as of June 19.

The affected chip families include A12, A13, S4, and S5. In device terms, that means iPhone XS, XS Max, XR, iPhone 11 series, iPhone SE second generation, iPad Air third generation, iPad mini fifth generation, iPad eighth generation, Apple Watch Series 4 and 5, first-generation Apple Watch SE, and HomePod mini. A11 is not affected. A14 and later appear to be out of reach.

The experts described the A12X and A12Z support as theoretically possible but not yet implemented. That covers iPad Pro models from 2018 and 2020, meaning the vulnerability boundary may expand.

The root cause is a hardware flaw in the USB controller Synopsys DWC2 USB used by Apple in these chips. The controller stores incoming USB Setup packets via DMA, buffers up to three, then resets its write pointer on the fourth by decrementing it by a fixed 24 bytes. It also accepts smaller-than-standard packets and increments the pointer only by the actual bytes written. That mismatch accumulates into a repeatable buffer underflow, stepping the write pointer backwards through memory 12 bytes at a time.

“The DesignWare USB controller stores up to three consecutive Setup packets in memory. Upon receiving a fourth Setup transaction, the DMA base address gets reset to its starting position before writing, akin to a ring buffer mechanism.

After writing each received packet, the controller increments DOEPDMA by the size of data written. The reset operation is implemented by decrementing DOEPDMA by 24.” continues the report.

“The core issue arises because the controller also accepts smaller packets (though always stores in 4-byte chunks).”

What makes this dangerous on A12 and A13 specifically is how Apple configured the USB DART, the chip’s memory mapping unit, inside SecureROM. On these devices it runs in bypass mode, so the underflowing DMA pointer can reach and overwrite arbitrary SRAM. A11 avoids the problem because its USB driver manually resets the DMA address after every packet, preventing accumulation. A14 and later configure DART correctly, which Paradigm Shift says makes the same vulnerability unexploitable on newer hardware.

Getting to code execution differs between the two chips. On A12 devices, the DMA buffer is located next to the USB task stack in memory, allowing attackers to overwrite control data and gain code execution during a task switch.

A13 is harder because Pointer Authentication protects stack-stored return addresses. Paradigm Shift bypassed it in stages: corrupting DART-related heap structures to create limited write primitives, overwriting a panic depth counter to make the chip loop on errors instead of rebooting, and then overwriting the USB interrupt handler pointer in BSS so the next USB interrupt runs attacker-supplied code. Either path ends at EL1, the chip’s privileged execution mode, inside SecureROM.

Once there, usbliter8 injects a custom USB request handler and stamps PWND:[usbliter8] into the device’s USB serial string. From that position an attacker can temporarily demote the SoC’s production mode or boot a raw, unsigned iBoot image with no signature checks, stepping entirely outside Apple’s chain of trust. The Secure Enclave is not shown to be compromised in this research. Paradigm Shift warns that BootROM-level control may open new routes for attacking it, but that work hasn’t been demonstrated yet.

The newly disclosed usbliter8 exploit is being compared to checkm8, the landmark 2019 SecureROM vulnerability that permanently affected Apple A5–A11 devices and could not be patched through software updates. Like checkm8, usbliter8 requires physical access and DFU mode, but it extends the same unpatchable condition to newer A12 and A13 chips. Checkm8 enabled years of jailbreaking, forensic acquisition, and custom boot environments, and researchers believe usbliter8 could open similar possibilities for a new generation of Apple devices.

For most personal users the practical risk is limited: an attacker needs the physical device, the right cable, and the knowledge to force DFU mode, which is not a trivial barrier in everyday life. For enterprise security teams, government agencies, and anyone running sensitive operations on affected hardware, this is a different category of problem. Physical security boundaries that previously existed no longer do. Inventory every A12, A13, S4, and S5 device in sensitive roles, accelerate refresh cycles toward A14 or newer, establish strict policies around DFU mode and untrusted USB connections, and treat physical device custody as a security control rather than an administrative detail. The code is public, which is usually how a research demo becomes someone else’s operational tool.

“While newer generations have addressed the underlying issue, affected A12 and A13 devices will carry it for the remainder of their lifetime.” concludes the report. “For those who have followed the history of iPhone exploitation and jailbreaking, this research is a reminder that the BootROM still occasionally has a surprise left to give.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, usbliter8)

❌
❌