HomeSecurityIntellexa: 15 zero-day vulnerabilities exploited since 2021

Intellexa: Exploiting 15 zero-day vulnerabilities since 2021

One of the most active and controversial spyware in recent years, Intellexa, is back in the spotlight, as according to a recent investigation, it has exploited 15 zero-day vulnerabilities since 2021 for targeted attacks on devices iOS and Android. Despite the sanctions it has received from the US, Intellexa's network appears to remain extremely active and technically sophisticated, with attacks recorded in countries such as Saudi Arabia, Pakistan, Egypt and other areas of high geopolitical interest.

Intellexa zero-day Predator spyware

Predator and commercial espionage: Intellexa's business engine

The company has become internationally known for developing the Predator, a software that allows complete remote control of target devices. Although it is under sanctions, Intellexa continues to operate through a network of front companies, which allow it to maintain customers worldwide and avoid direct connection to its activities.

See also: Researchers uncover over 30 vulnerabilities in AI coding tools

According to Google Cloud who actively monitor commercial spyware companies, Intellexa is one of the largest “consumers of zero-day exploits” targeting mobile browsers. Of the approximately 70 previously unknown vulnerabilities discovered in the past three years, the company is reportedly behind at least 15 exploit chains, including Remote Code Execution (RCE), Sandbox Escape , and Local Privilege Escalation.

CVEVulnerability TypeVendorAffected Product
CVE-2025-48543SBX+LPEGoogleAndroid
CVE-2025-6554RCEGoogleChrome
CVE-2023-41993RCEAppleiOS
CVE-2023-41992SBX+LPEAppleiOS
CVE-2023-41991LPEAppleiOS
CVE-2024-4610LPEARMMali
CVE-2023-4762RCEGoogleChrome
CVE-2023-3079RCEGoogleChrome
CVE-2023-2136SBXGoogleSkia
CVE-2023-2033RCEGoogleChrome
CVE-2021-38003RCEGoogleChrome
CVE-2021-38000RCEGoogleChrome
CVE-2021-37976SBXGoogleChrome
CVE-2021-37973SBXGoogleChrome
CVE-2021-1048SBX+LPEGoogleAndroid

Attacks via hidden links and stealth delivery

Intellexa attacks most often begin with a malicious linksent via encrypted messaging apps — an environment where content control is virtually impossible. Once the user opens the link, their device is taken to a chain of exploits that silently execute and lead to the installation of Predator.

See also: React2Shell vulnerability on CISA's KEV List – 30 organizations breached

Intellexa: Exploiting 15 zero-day vulnerabilities since 2021

The affected vendors (Apple, Google, and others) have already patched the security holes, but the speed with which Intellexa is replacing its tools—by purchasing new exploit chains from external developers—gives it a significant operational advantage.

The Egypt case: The exploit chain “smack”

One of the most notable cases reported involves an attack in Egypt, which used a chain of exploits internally codenamed “smack”. The attack begins by exploiting CVE-2023-41993 in Safari, using the JSKit, which provides memory read and write capabilities. This framework has been detected in numerous campaigns since 2021 and is considered by researchers to be particularly mature and actively maintained.

Sandbox escape and kernel penetration

In the second stage, the attack exploits two kernel vulnerabilities — CVE-2023-41991 and CVE-2023-41992 — to achieve sandbox escape, giving the final payload access to critical memory areas. This point essentially “opens the door” for the full installation of the spyware.

See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack

Intellexa: Exploiting 15 zero-day vulnerabilities since 2021

The “helper” and “watcher” modules: Predator's hidden function

The third stage includes two modules, known as helper and watcher:

  • The watcher acts as an anti-tracking system. It monitors whether the device has security tools, debugging features, is located in the US or Israel, or is running antivirus software such as McAfee or Norton. If it detects such indications, it automatically terminates the attack to prevent the exploit chain from being exposed.
  • The helper provides “real” spying capabilities. With custom frameworks (DMHooker and UMHooker), it can record voice calls , keystrokes , and take photos via the camera, while hiding related notifications by connecting to the iOS SpringBoard

Voice recording files are stored in .m4a format in a special path, while the metadata of compiled modules reveals internal names and pipelines connected to the Intellexa development ecosystem.

An ecosystem that will be hard to stop

Intellexa’s trajectory from 2021 to today demonstrates that commercial spyware vendors have evolved into global cyber-enterprise players, with consistency, expertise, and significant resources. Despite sanctions and revelations, the company continues to find ways to act, adapt, and remain one of the most resilient spyware ecosystems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS