Apple has patched two zero-day vulnerabilities (CVE-2023-41064, CVE-2023-41061) exploited to deliver NSO Group's Pegasus spyware.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab shared.
“The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.”
About the vulnerabilities
Read more
Tags: version, Hot stuff, 2023, attack, images, exploit, Account, citizen, NSO, iMessage, Pegasus, Zero-days, News, Apple, Pegasus Spyware