Attackers, whose identities remain unknown, have exploited vulnerabilities in Apple’s Safari browser’s WebKit engine, which is utilized for rendering web content across the company’s operating systems. One of the vulnerabilities allowed attackers to bypass the protective “sandbox” that restricts access to other parts of the operating system. This specific vulnerability, identified as CVE-2023-32409, has been patched in the latest security updates released by Apple. The attacks and the suspected culprits have not been disclosed by Google’s Threat Analysis Group (TAG), Amnesty International, or Apple.
Apple also addressed two other vulnerabilities in WebKit through its Rapid Security Response out-of-band patches. These vulnerabilities, reported by anonymous researchers, enabled attackers to access sensitive information and execute arbitrary code by exploiting an out-of-bounds read flaw and a use-after-free condition.
Furthermore, security researcher Amat Cama of Vigilant Labs discovered a bug in the cellular function of iPhone 8 and X, which could be exploited to remotely execute arbitrary code. Ivan Fratric from Google’s Project Zero identified a flaw in the Telephony function of iPhone 8 and later models, iPad Pro, Air, and mini, which could crash applications and also be abused for remote code execution.
Apple has released security updates for various systems, including Safari web browser, watchOS, tvOS, iOS, iPadOS, and macOS.


