Apple has released urgent security updates to fix three new zero-day vulnerabilities that could allow attacks on iPhone and Mac. These updates bring the total number of zero-days that have been fixed to date to 16.
See also: Trend Micro fixes critical zero-day vulnerability in Apex One

Two of the bugs were discovered in the WebKit browser engine and affect its security. They allow attackers to bypass signature validation using malicious applications or even execute arbitrary code via maliciously crafted web pages.
The third is in the kernel framework , which provides APIs and support for kernel extensions and device drivers that run in the kernel . Local attackers can exploit this vulnerability (CVE-2023-41992) to gain uncontrolled access and privileges.
Apple has patched three zero-day vulnerabilities in macOS 12.7/13.6, iOS 16.7/17.0.1, iPadOS 16.7/17.0.1, and watchOS 9.6.3/10.0.1. These updates addressed a certificate validation issue and included improved checks.
"Apple has received a report that this issue may have been actively exploited against versions of iOS prior to iOS 16.7," revealed in security advisories describing the security flaws.
See also: Mozilla: Fixes zero-day affecting Firefox and Thunderbird
The list of affected devices includes older and newer device models and includes:
- iPhone 8 and later
- iPad mini 5th generation and later
- Macs running macOS Monterey and later
- Apple Watch Series 4 and later

Bill Marczak of Citizen Lab and Maddie Stone of Google 's Threat Analysis Team discovered and reported three zero-days.
Although Apple has not yet disclosed details about how the vulnerabilities were exploited, security researchers at Citizen Lab and Google's Threat Analysis Team have uncovered several zero-day vulnerabilities that are being exploited in targeted spyware on high-risk individuals, including journalists, opposition politicians, and dissidents.
Citizen Lab uncovered two additional zero-days (CVE-2023-41061 and CVE-2023-41064), which were also patched by Apple via emergency security updates last month. These vulnerabilities were exploited as part of a zero-click exploit chain, known as BLASTPASS , to infect fully patched iPhones with NSO Group's Pegasus spyware .
See also: Adobe: Critical zero-days threaten Acrobat and Reader
Since the beginning of the year, Apple has also fixed:
- two zero-days (CVE-2023-37450 and CVE-2023-38606) in July
- three zero-days (CVE-2023-32434, CVE-2023-32435, and CVE-2023-32439) in June
- three more zero-days (CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373) in May
- two zero-days (CVE-2023-28206 and CVE-2023-28205) in April
- and a WebKit zero-day (CVE-2023-23529) in February
